diff --git a/rules/windows/malware/win_mal_ursnif.yml b/rules/windows/malware/win_mal_ursnif.yml index cf696cf73..a0c51c74a 100644 --- a/rules/windows/malware/win_mal_ursnif.yml +++ b/rules/windows/malware/win_mal_ursnif.yml @@ -16,7 +16,7 @@ logsource: detection: selection: EventID: 13 - TargetObject|contains: '\Software\AppDataLow\Software\Microsoft\\' + TargetObject|contains: '\Software\AppDataLow\Software\Microsoft\' condition: selection falsepositives: - Unknown