From 8dbeedf7282c70e3368ff8f396cb232803147366 Mon Sep 17 00:00:00 2001 From: Wagga <6437862+wagga40@users.noreply.github.com> Date: Mon, 29 Aug 2022 20:14:47 +0200 Subject: [PATCH] Update file_event_win_powershell_startup_shortcuts.yml --- .../file_event/file_event_win_powershell_startup_shortcuts.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/file_event/file_event_win_powershell_startup_shortcuts.yml b/rules/windows/file_event/file_event_win_powershell_startup_shortcuts.yml index 4a4f81d67..066435f42 100644 --- a/rules/windows/file_event/file_event_win_powershell_startup_shortcuts.yml +++ b/rules/windows/file_event/file_event_win_powershell_startup_shortcuts.yml @@ -24,5 +24,5 @@ detection: condition: selection falsepositives: - Unknown - - Depending on your environment accepted applications may leverage this at times. It is recomended to search for anomolies inidicative of malware. + - Depending on your environment accepted applications may leverage this at times. It is recomended to search for recommended inidicative of malware. level: high