diff --git a/rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml b/rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml index 978e75bf6..2518b05ed 100644 --- a/rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml +++ b/rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml @@ -22,7 +22,7 @@ detection: condition: selection falsepositives: - Legitimate PowerShell scripts -level: low +level: medium tags: - attack.credential_access - attack.t1003.006