diff --git a/rules/windows/sysmon/sysmon_wmi_module_load.yml b/rules/windows/sysmon/sysmon_wmi_module_load.yml index 2c302532f..8c660f19e 100644 --- a/rules/windows/sysmon/sysmon_wmi_module_load.yml +++ b/rules/windows/sysmon/sysmon_wmi_module_load.yml @@ -34,6 +34,7 @@ detection: - '\DeviceCensus.exe' - '\CompatTelRunner.exe' - '\sdiagnhost.exe' + - '\SIHClient.exe' condition: selection and not filter fields: - ComputerName