Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
We see a lot of false positives for this rule. IcedID uses google analytics cookie names for these values, and this is what this rule detects. This is a problem, because you'll find a lot of google analytics cookies in Pcaps, python scripts, html files, etc. I suggest restricting the detection to PE files, should solve most of the false positives for this
- Loading branch information