cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3209
Views
5
Helpful
3
Replies

How to whitelist a command-line argument?

tmbarnhart
Level 1
Level 1

We have a "Cloud IOC: W32.WMIProcessCores.ioc" triggering.

2020-01-27_085558.jpg

It's a legit Microsoft SCCM inventory process.

I don't want to whitelist all "wmic.exe" paths or SHAs, only this specific command-line.

Any guidance?

Thanks,

Troy

3 Replies 3

Muhammad Awais Khan
Cisco Employee
Cisco Employee

Hi,

 

You can white list this specific path by adding below in your existing exclusion sets or new:

 

Under the exclusion set, Choose 'Path' and value = CSIDL_WINDOWS\System32\Wbem

Troja007
Cisco Employee
Cisco Employee

Hello @tmbarnhart,

there is an open FR for this: AMP4E-I-1143 

You may query your Cisco Representative to get frequently updated for this.

Greetings,

Thorsten

Any updates on this one? :)
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: