We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A lot of flood by
Process accessed: RuleName: technique_id=T1055,technique_name=Process Injection SourceImage: C:\Program Files (x86)\Kaspersky Lab\KES.12.2.0\avp.exe
It would be better to exclude directory C:\Program Files (x86)\Kaspersky Lab\, because various Kaspersky Lab security tools are located there.
C:\Program Files (x86)\Kaspersky Lab\
C:\Program Files (x86)\Kaspersky Lab\KES.12.2.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security for Windows Server C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent C:\Program Files (x86)\Kaspersky Lab\NetworkAgent
C:\Program Files (x86)\Kaspersky Lab\KES.12.2.0
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security for Windows Server
C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent
C:\Program Files (x86)\Kaspersky Lab\NetworkAgent
I also suggest changing the path here too:
sysmon-modular/12_13_14_registry_event/exclude_kaspersky_lab_internet_security.xml
Lines 5 to 6 in a9ff298
The text was updated successfully, but these errors were encountered:
No branches or pull requests
A lot of flood by
It would be better to exclude directory
C:\Program Files (x86)\Kaspersky Lab\
, because various Kaspersky Lab security tools are located there.C:\Program Files (x86)\Kaspersky Lab\KES.12.2.0
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security for Windows Server
C:\Program Files (x86)\Kaspersky Lab\Endpoint Agent
C:\Program Files (x86)\Kaspersky Lab\NetworkAgent
I also suggest changing the path here too:
sysmon-modular/12_13_14_registry_event/exclude_kaspersky_lab_internet_security.xml
Lines 5 to 6 in a9ff298
The text was updated successfully, but these errors were encountered: