Skip to content

Conversation

@gustavo89587
Copy link

This PR refines the rule description and expands the false positive guidance for Sysmon Configuration Change (Event ID 16) to provide clearer operational context for analysts.
No detection logic was changed.

This change adds suspicious execution paths to the existing 7-Zip password compression rule to improve context and reduce benign usage noise.
…ion change rule

This PR refines the rule description and expands the false positive guidance for Sysmon Configuration Change (Event ID 16) to provide clearer operational context for analysts.
No detection logic was changed.
@github-actions github-actions bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Jan 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant