diff --git a/rules/windows/process_creation/win_susp_sysprep_appdata.yml b/rules/windows/process_creation/win_susp_sysprep_appdata.yml index daf98b204..56694bf67 100644 --- a/rules/windows/process_creation/win_susp_sysprep_appdata.yml +++ b/rules/windows/process_creation/win_susp_sysprep_appdata.yml @@ -17,7 +17,7 @@ detection: selection: CommandLine|contains|all: - 'sysprep.exe' - - '\AppData\\' + - '\AppData\' condition: selection falsepositives: - False positives depend on scripts and administrative tools used in the monitored environment