diff --git a/detection/exfil/high_disk_bytes_read.sql b/detection/exfil/high_disk_bytes_read.sql index 8d89f84..d304c2e 100644 --- a/detection/exfil/high_disk_bytes_read.sql +++ b/detection/exfil/high_disk_bytes_read.sql @@ -104,8 +104,8 @@ WHERE 'wineserver', 'yay', 'ykman-gui', - 'zsh' - 'ZwiftAppMetal', + 'zsh', + 'ZwiftAppMetal' ) AND NOT p0.path IN ( '/System/Volumes/Preboot/Cryptexes/App/System/Applications/Safari.app/Contents/XPCServices/com.apple.Safari.BrowserDataImportingService.xpc/Contents/MacOS/com.apple.Safari.BrowserDataImportingService',