diff --git a/rules/windows/process_creation/win_multiple_suspicious_cli.yml b/rules/windows/process_creation/win_multiple_suspicious_cli.yml index a1a059631..c87f44d9e 100644 --- a/rules/windows/process_creation/win_multiple_suspicious_cli.yml +++ b/rules/windows/process_creation/win_multiple_suspicious_cli.yml @@ -6,6 +6,7 @@ references: - https://car.mitre.org/wiki/CAR-2013-04-002 author: juju4 date: 2019/01/16 +modified: 2021/06/13 tags: - car.2013-04-002 logsource: