diff --git a/rules/windows/process_creation/win_bad_opsec_sacrificial_processes.yml b/rules/windows/process_creation/win_bad_opsec_sacrificial_processes.yml index 206dd9fa2..4b9294d8c 100644 --- a/rules/windows/process_creation/win_bad_opsec_sacrificial_processes.yml +++ b/rules/windows/process_creation/win_bad_opsec_sacrificial_processes.yml @@ -16,9 +16,9 @@ logsource: product: windows detection: selection: - CommandLine: - - '*\WerFault.exe' - - '*\rundll32.exe' + CommandLine|endswith: + - '\WerFault.exe' + - '\rundll32.exe' condition: selection falsepositives: - Unlikely