diff --git a/rules/windows/sysmon/sysmon_process_hollowing.yml b/rules/windows/sysmon/sysmon_process_hollowing.yml index 3f5fbf9b1..0a25fa467 100644 --- a/rules/windows/sysmon/sysmon_process_hollowing.yml +++ b/rules/windows/sysmon/sysmon_process_hollowing.yml @@ -20,7 +20,7 @@ detection: filters: Image|endswith: - '\chrome.exe' - - '\opeara.exe' + - '\opera.exe' - '\firefox.exe' - '\MicrosoftEdge.exe' condition: selection and not filters