diff --git a/rules/proxy/proxy_turla_comrat.yml b/rules/proxy/proxy_turla_comrat.yml index c546ddb69..4423e4a74 100644 --- a/rules/proxy/proxy_turla_comrat.yml +++ b/rules/proxy/proxy_turla_comrat.yml @@ -11,7 +11,7 @@ logsource: category: proxy detection: selection: - c-uri|contains: '/index/index.php?h=' + c-uri|contains: '/index/index.php\?h=' condition: selection falsepositives: - Unknown