Update win_susp_wmi_login.yml

This commit is contained in:
Jonhnathan
2020-11-19 22:47:20 -03:00
committed by GitHub
parent ea385767b9
commit 4f4fcbc576
+1 -1
View File
@@ -13,7 +13,7 @@ logsource:
detection:
selection:
EventID: 4624
ProcessName|endswith: "\\WmiPrvSE.exe"
ProcessName|endswith: '\WmiPrvSE.exe'
condition: selection
falsepositives:
- Monitoring tools