From 265faf6337dbcd8ce7ffc10131c6d3d784fa8c1f Mon Sep 17 00:00:00 2001 From: securepeacock <92804416+securepeacock@users.noreply.github.com> Date: Sun, 24 Oct 2021 14:15:04 -0400 Subject: [PATCH] Update sysmon_powershell_startup_shortcuts.yml --- .../file_event/sysmon_powershell_startup_shortcuts.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/windows/file_event/sysmon_powershell_startup_shortcuts.yml b/rules/windows/file_event/sysmon_powershell_startup_shortcuts.yml index 2f0b954bf..70c82df34 100644 --- a/rules/windows/file_event/sysmon_powershell_startup_shortcuts.yml +++ b/rules/windows/file_event/sysmon_powershell_startup_shortcuts.yml @@ -1,4 +1,4 @@ -title: PowerShell writing startup shortcuts +title: PowerShell Writing Startup Shortcuts id: 92fa78e7-4d39-45f1-91a3-8b23f3f1088d description: Attempts to detect PowerShell writing startup shortcuts. status: experimental @@ -17,7 +17,7 @@ tags: - attack.registry_run_keys_/_startup_folder - attack.t1547.001 date: 2021/10/24 -author: Christopher Peacock (@securepeacock), SCYTHE +author: Christopher Peacock '@securepeacock', SCYTHE level: high logsource: product: windows