diff --git a/rules/windows/process_creation/sysmon_apt_sourgrum.yml b/rules/windows/process_creation/sysmon_apt_sourgrum.yml index 8ea9ea531..1a6c50cd3 100644 --- a/rules/windows/process_creation/sysmon_apt_sourgrum.yml +++ b/rules/windows/process_creation/sysmon_apt_sourgrum.yml @@ -1,9 +1,7 @@ title: SOURGUM Actor Behaviours id: 7ba08e95-1e0b-40cd-9db5-b980555e42fd description: Suspicious behaviours related to an actor tracked by Microsoft as SOURGUM -author: - - MSTIC - - FPT.EagleEye +author: MSTIC, FPT.EagleEye status: experimental level: high references: