diff --git a/rules/windows/process_creation/proc_creation_win_susp_conhost_option.yml b/rules/windows/process_creation/proc_creation_win_susp_conhost_option.yml index abb6086cc..a337462cc 100644 --- a/rules/windows/process_creation/proc_creation_win_susp_conhost_option.yml +++ b/rules/windows/process_creation/proc_creation_win_susp_conhost_option.yml @@ -1,4 +1,4 @@ -title: Suspicius Conhost Legacy Option +title: Suspicious Conhost Legacy Option id: 3037d961-21e9-4732-b27a-637bcc7bf539 status: experimental description: ForceV1 asks for information directly from the kernel space. Conhost connects to the console application