cuckoosandbox / community

Repository of modules and signatures contributed by the community
323 stars 175 forks source link

Safelisting powershell in antivm_disksize #487

Closed cccs-kevin closed 2 years ago

cccs-kevin commented 3 years ago

After submitting thousands of PowerShell files, I have determined that this signature is raised an overwhelming majority of the time for benign files. Therefore I suggest that we safelist powershell.exe.