diff --git a/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml b/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml index 007a8d084..ce3c4e440 100644 --- a/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml +++ b/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml @@ -19,7 +19,7 @@ detection: - 'TVpTAQEAAAAEAAAA' condition: selection falsepositives: - - Unlikley + - Unlikely level: high tags: - attack.execution