diff --git a/Exclusion Rules/900000-exclusion_rules.xml b/Exclusion Rules/900000-exclusion_rules.xml index 8e44e38..2b8e596 100644 --- a/Exclusion Rules/900000-exclusion_rules.xml +++ b/Exclusion Rules/900000-exclusion_rules.xml @@ -685,4 +685,19 @@ DLL file created by printer spool service, possible malware binary drop from PrintNightmare exploit no_full_log + + + 67027 + (?i)^C:\\\\Program Files \(x86\)\\\\[\w\d\.-]+\\\\NinjaRMMAgent\.exe$ + (?i)^C:\\\\Windows\\\\SysWOW64\\\\sc\.exe$|(?i)^C:\\\\Program Files\\\\SentinelOne\\\\Sentinel Agent \d+\.\d+\.\d+\.\d+\\\\SentinelCtl\.exe$|(?i)^C:\\\\Windows\\\\SysWOW64\\\\WindowsPowerShell\\\\v1\.0\\\\powershell\.exe$|(?i)^C:\\\\Windows\\\\SysWOW64\\\\cmd\.exe$ + Exclude Windows Common Process Creation for NinjaRMM. + no_full_log + + + + 67027 + (?i)^C:\\\\Windows\\\\LTSvc\\\\LTSVC\.exe$ + Exclude Windows Common Process Creation for LTSVC. + no_full_log +