From 4f4fcbc576976710f46a6e176ae6bbbfa08eb64d Mon Sep 17 00:00:00 2001 From: Jonhnathan Date: Thu, 19 Nov 2020 22:47:20 -0300 Subject: [PATCH] Update win_susp_wmi_login.yml --- rules/windows/builtin/win_susp_wmi_login.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/builtin/win_susp_wmi_login.yml b/rules/windows/builtin/win_susp_wmi_login.yml index cf0bad0c5..98835de02 100644 --- a/rules/windows/builtin/win_susp_wmi_login.yml +++ b/rules/windows/builtin/win_susp_wmi_login.yml @@ -13,7 +13,7 @@ logsource: detection: selection: EventID: 4624 - ProcessName|endswith: "\\WmiPrvSE.exe" + ProcessName|endswith: '\WmiPrvSE.exe' condition: selection falsepositives: - Monitoring tools