diff --git a/rules/windows/builtin/win_mal_wceaux_dll.yml b/rules/windows/builtin/win_mal_wceaux_dll.yml index df16fe303..e188aa447 100644 --- a/rules/windows/builtin/win_mal_wceaux_dll.yml +++ b/rules/windows/builtin/win_mal_wceaux_dll.yml @@ -21,7 +21,7 @@ detection: - 4658 - 4660 - 4663 - ObjectName: '*\wceaux.dll' + ObjectName|endswith: '\wceaux.dll' condition: selection falsepositives: - Penetration testing