FP on 2856495 - "ETPRO HUNTING If-Unmodified-Since Header with Microsoft BITS User-Agent"

Hi,

We are getting tons of FP hits on this rule in which the Host: header ends with cdn.office.net. I see we are already excluding other Windows/Microsoft domains and I presume we should add something like this to the rule:
content:!"office.net";endswith;
or
content:!"cdn.office.net";endswith;

Thanks
Kevin

1 Like

Thanks for the report Kevin, will take a look and see about getting the sig updated for todays release.

JT

1 Like