FIM and Windows Updates Best Practices

Hi all,

When using the File Integrity Module integration, is there a way to tune out expected behavior from Windows updates? Been having a lot of alerts following regular updates.

EDIT: I thought about adding an exception to the alert for TrustedInstaller but pretty sure with enough effort, attackers can act as TrustedInstaller

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.