LoFP LoFP / legitimate rclone usage

Techniques

Sample rules

Rclone Config File Creation

Description

Detects Rclone config files being created

Detection logic

condition: selection
selection:
  TargetFilename|contains|all:
  - :\Users\
  - \.config\rclone\