When running Loki on Linux, Filename IOCs that reside in the Windows root folder, such as C:\\Program.exe will be matched in every (sub)folder in the scan directory.
Example scan results, where I've placed two non-malicious files in an 'unrelated' subfolder:
When running Loki on Linux, Filename IOCs that reside in the Windows root folder, such as
C:\\Program.exe
will be matched in every (sub)folder in the scan directory. Example scan results, where I've placed two non-malicious files in an 'unrelated' subfolder: