cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
1268
Views
0
Helpful
3
Replies
tmbarnhart
Beginner

How to whitelist a command-line argument?

We have a "Cloud IOC: W32.WMIProcessCores.ioc" triggering.

2020-01-27_085558.jpg

It's a legit Microsoft SCCM inventory process.

I don't want to whitelist all "wmic.exe" paths or SHAs, only this specific command-line.

Any guidance?

Thanks,

Troy

3 REPLIES 3
Muhammad Awais Khan
VIP Rising star

Hi,

 

You can white list this specific path by adding below in your existing exclusion sets or new:

 

Under the exclusion set, Choose 'Path' and value = CSIDL_WINDOWS\System32\Wbem

Troja007
Cisco Employee

Hello @tmbarnhart,

there is an open FR for this: AMP4E-I-1143 

You may query your Cisco Representative to get frequently updated for this.

Greetings,

Thorsten

Any updates on this one? :)
Content for Community-Ad