diff --git a/rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml b/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml similarity index 93% rename from rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml rename to rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml index 2d785c0f9..3f0a28d40 100644 --- a/rules/windows/builtin/code_integrity/win_codeintegrity_failed_dll_load.yml +++ b/rules/windows/builtin/code_integrity/win_codeintegrity_attempted_dll_load.yml @@ -1,6 +1,6 @@ -title: Code Integrity Blocked DLL Load +title: Code Integrity Attempted DLL Load id: f8931561-97f5-4c46-907f-0a4a592e47a7 -description: Detects DLL load events that got blocked by Windows code integrity checks due to not meeting the Windows/Antimalware signing level requirements +description: Detects attempted DLL load events that didn't meet signing level requirements author: Florian Roth, Nasreddine Bencherchali (update) status: experimental references: