From acfdb591d05eb27f98b7bedece27da95ff260d75 Mon Sep 17 00:00:00 2001 From: Florian Roth Date: Sun, 29 Jul 2018 16:22:39 +0200 Subject: [PATCH] fiox: Typo in description fixed --- rules/windows/builtin/win_susp_process_creations.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/builtin/win_susp_process_creations.yml b/rules/windows/builtin/win_susp_process_creations.yml index 10b6a12ba..b6274a288 100644 --- a/rules/windows/builtin/win_susp_process_creations.yml +++ b/rules/windows/builtin/win_susp_process_creations.yml @@ -1,7 +1,7 @@ --- action: global title: Suspicious Process Creation -description: Detects suspicious process starts on Windows systems bsed on keywords +description: Detects suspicious process starts on Windows systems based on keywords status: experimental references: - https://www.swordshield.com/2015/07/getting-hashes-from-ntds-dit-file/