Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Suggested additions to Microsoft Defender ProcessCreation event #185

Open
cyb3rxp opened this issue Aug 21, 2023 · 0 comments
Open

Suggested additions to Microsoft Defender ProcessCreation event #185

cyb3rxp opened this issue Aug 21, 2023 · 0 comments

Comments

@cyb3rxp
Copy link

cyb3rxp commented Aug 21, 2023

Hi Olaf,

I would recommend to add those exclusions for Windows Defender for endpoints (EDR):
C:\Program Files\Windows Defender Advanced Threat Protection\SenseNdr.exe
C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe

There are also other binaries, but they are located within the C:\Program Files\Windows Defender\ folder, which is already excluded.

HTH.
Thanks.

Phil

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant