diff --git a/Exclusion Rules/900000-exclusion_rules.xml b/Exclusion Rules/900000-exclusion_rules.xml index dbe78b0..c31191c 100644 --- a/Exclusion Rules/900000-exclusion_rules.xml +++ b/Exclusion Rules/900000-exclusion_rules.xml @@ -800,4 +800,13 @@ no_full_log Exclude Prefetch file creation is normal behavior whenever a process executes by svchost.exe. + + + 92214 + no_full_log + Suspicious file created by Microsoft Office process: $(win.eventdata.image) created $(win.eventdata.targetFilename) + + T1027 + +