Skip to content

Commit 29783d1

Browse files
authored
Update smconfig.xml
1 parent 14d3fb7 commit 29783d1

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

smconfig.xml

+2
Original file line numberDiff line numberDiff line change
@@ -191,6 +191,7 @@
191191
<CreateRemoteThread onmatch="exclude">
192192
<!--COMMENT: Exclude mostly-safe sources and log anything else.-->
193193
<SourceImage condition="is">C:\Windows\system32\wbem\WmiPrvSE.exe</SourceImage>
194+
<SourceImage condition="begin with">C:\windows\freeEDR\</SourceImage>
194195
<SourceImage condition="is">C:\Windows\system32\svchost.exe</SourceImage>
195196
<SourceImage condition="is">C:\Windows\system32\wininit.exe</SourceImage>
196197
<SourceImage condition="is">C:\Windows\system32\csrss.exe</SourceImage>
@@ -258,6 +259,7 @@
258259
<SourceImage condition="is">System</SourceImage> <!-- to exclude when the source image is a system process or windows process, its more interested to check if someone accessing or writing to a system process -->
259260
<SourceImage condition="is">C:\Windows\Sysmon.exe</SourceImage>
260261
<SourceImage condition="is">C:\Windows\Sysmon64.exe</SourceImage>
262+
<SourceImage condition="begin with">C:\Windows\freeEDR\</SourceImage>
261263
<SourceImage condition="begin with">C:\Program Files\Microsoft Visual Studio\</SourceImage>
262264
<SourceImage condition="is">C:\Windows\Explorer.EXE</SourceImage>
263265
<SourceImage condition="is">C:\Program Files\Synaptics\SynTP\SynTPEnh.exe</SourceImage>

0 commit comments

Comments
 (0)