mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-11-04 13:53:16 +00:00
Update 900000-exclusion_rules.xml
This commit is contained in:
committed by
GitHub
parent
6bb89a23db
commit
2ca470be98
@@ -258,7 +258,7 @@
|
||||
</rule>
|
||||
<!-- Exclude MicroSoft Teams -->
|
||||
<rule id="900040" level="1">
|
||||
<if_sid>92910</if_sid>
|
||||
<if_sid>92910,106117</if_sid>
|
||||
<field name="win.eventdata.sourceImage" type="pcre2">(?i)C:\\\\ProgramData\\\\.*\\\\Microsoft\\\\Teams\\\\current\\\\Teams.exe$|</field>
|
||||
<description>Exclude Microsoft Teams</description>
|
||||
<options>no_full_log</options>
|
||||
|
||||
Reference in New Issue
Block a user