-
Notifications
You must be signed in to change notification settings - Fork 95
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New Expected Path #4
Comments
I haven't seen this libraries loaded by msedge in my lab. Could it be something custom to the environment? |
It's a known alternate location for the files. And judging by the logic of the query I think the reason it's listed Suspicious is because it's location is not added to Expected locations, not because it's unusual to be loaded by Edge. |
I can see Edge is one of the expected programs listed as using this libraries (andalso possible target for hijacking) |
I've synced the csf file. Let me know if it doesn't work. |
Hello, I believe this path %system32%\wbem should be added as Expected Location for both DLLs. Seem false positives:
![image](https://user-images.githubusercontent.com/23101316/200793942-f7d72427-c5da-4c84-8bc8-5bd10ecba6e7.png)
wbemprox.dll
wbemsvc.dll
The text was updated successfully, but these errors were encountered: