diff --git a/rules/windows/process_creation/win_susp_sqldumper_activity.yml b/rules/windows/process_creation/win_susp_sqldumper_activity.yml index 29ddc6b38..49c33e0c4 100644 --- a/rules/windows/process_creation/win_susp_sqldumper_activity.yml +++ b/rules/windows/process_creation/win_susp_sqldumper_activity.yml @@ -1,4 +1,4 @@ -title: Dumping process via sqldumper.exe +title: Dumping Process via Sqldumper.exe id: 23ceaf5c-b6f1-4a32-8559-f2ff734be516 description: Detects process dump via legitimate sqldumper.exe binary status: experimental