diff --git a/rules/windows/file_event/sysmon_quarkspw_filedump.yml b/rules/windows/file_event/sysmon_quarkspw_filedump.yml index 2a582eaa3..fb8c03e24 100755 --- a/rules/windows/file_event/sysmon_quarkspw_filedump.yml +++ b/rules/windows/file_event/sysmon_quarkspw_filedump.yml @@ -18,7 +18,7 @@ logsource: detection: selection: # Sysmon: File Creation (ID 11) - TargetFilename: '*\AppData\Local\Temp\SAM-*.dmp*' + TargetFilename|contains: '\AppData\Local\Temp\SAM-*.dmp' condition: selection falsepositives: - Unknown