Update rules/windows/process_creation/proc_creation_win_susp_process_hacker.yml
Co-authored-by: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com>
This commit is contained in:
@@ -22,6 +22,7 @@ detection:
|
||||
- OriginalFileName:
|
||||
- 'ProcessHacker.exe'
|
||||
- 'Process Hacker'
|
||||
- 'SystemInformer.exe'
|
||||
- Description:
|
||||
- 'Process Hacker'
|
||||
- 'System Informer'
|
||||
|
||||
Reference in New Issue
Block a user