We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
进程ID:2092 操作进程:C:\Windows\System32\svchost.exe 操作进程命令行:C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule 父进程ID:1476 父进程:C:\Windows\System32\services.exe 父进程命令行:C:\Windows\system32\services.exe
截图 (可选)
触发场景描述 (可选)平均一小时出现一次
Windows version
Huorong version
Huorong logs (open the Huorong log interface, select the corresponding logs, export/copy-paste them here)
Screenshots (optional)
Methods to reproduce the issue (optional)
The text was updated successfully, but these errors were encountered:
支持 6.0 的时候解决
Sorry, something went wrong.
close JerryLinLinLin#26, JerryLinLinLin#27
fefaaf3
触犯规则:Suspicious.PowerShell.A 操作类型:【执行】 操作文件:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 操作结果:已阻止
进程ID:1964 操作进程:C:\Windows\System32\svchost.exe 操作进程命令行:C:\Windows\system32\svchost.exe -k netsvcs -p 父进程ID:1364 父进程:C:\Windows\System32\services.exe 父进程命令行:C:\Windows\system32\services.exe
个人怀疑是wuauserv服务(网上找了下),但是这个服务又是被禁用的,疑惑ing~,至于是不是计划任务里的,我不知道,没去找。这个行为和楼主的相似,我就直接贴过来了。
No branches or pull requests
触犯规则:Suspicious.RunFromSusPath.C
操作类型:【执行】
操作文件:C:\ProgramData\MEGAsync\MEGAupdater.exe
操作结果:已允许
进程ID:2092
操作进程:C:\Windows\System32\svchost.exe
操作进程命令行:C:\Windows\system32\svchost.exe -k netsvcs -p -s Schedule
父进程ID:1476
父进程:C:\Windows\System32\services.exe
父进程命令行:C:\Windows\system32\services.exe
截图 (可选)
触发场景描述 (可选)平均一小时出现一次
Windows version
Huorong version
Huorong logs (open the Huorong log interface, select the corresponding logs, export/copy-paste them here)
Screenshots (optional)
Methods to reproduce the issue (optional)
The text was updated successfully, but these errors were encountered: