Hello!! How are you? i need confirm an action when add exception for child process, i have several alerts for "WmiPrvSe.exe Rare Child Process" that are false positive, and im considering add to whitelist in the profile associated. For create it i need add parent process, child process and child process command, I need confirm if this works as a string? In other words, the child process will be excepted only if it is created from parent that i specified, right? I have other question, is there a way to create these exceptions "child process" for just one host, without the need to create a policy for just this host? Thanks very much!
... View more