filter_optional_thor_remote: ImagePath|startswith:
'C:\WINDOWS\TEMP\thor10-remote\thor64.exe' filter_main_defender_def_updates: ImagePath|startswith:
'C:\ProgramData\Microsoft\Windows Defender\Definition Updates\' condition:selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_* Falsepositives:
-Unknown Level:medium