From 1a26c174f2be199c12e9757318e30eb110c0ddea Mon Sep 17 00:00:00 2001 From: Wagga <6437862+wagga40@users.noreply.github.com> Date: Mon, 29 Aug 2022 07:47:27 +0200 Subject: [PATCH] Update proc_creation_win_inline_base64_mz_header.yml --- .../proc_creation_win_inline_base64_mz_header.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml b/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml index 007a8d084..ce3c4e440 100644 --- a/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml +++ b/rules/windows/process_creation/proc_creation_win_inline_base64_mz_header.yml @@ -19,7 +19,7 @@ detection: - 'TVpTAQEAAAAEAAAA' condition: selection falsepositives: - - Unlikley + - Unlikely level: high tags: - attack.execution