diff --git a/rules/windows/process_creation/proc_creation_win_archiver_iso_phishing.yml b/rules/windows/process_creation/proc_creation_win_archiver_iso_phishing.yml index de6c58641..17176eadc 100644 --- a/rules/windows/process_creation/proc_creation_win_archiver_iso_phishing.yml +++ b/rules/windows/process_creation/proc_creation_win_archiver_iso_phishing.yml @@ -1,6 +1,6 @@ title: Phishing Pattern ISO in Archive id: fcdf69e5-a3d3-452a-9724-26f2308bf2b1 -status: experminetal +status: experimental description: Detects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is open a signa of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web) author: Florian Roth references: