diff --git a/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml b/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml index 47e0aba3f..050c8db1a 100644 --- a/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml +++ b/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml @@ -33,7 +33,7 @@ detection: CommandLine|contains: - /i - -i - condition: selectionFindstr and (all of selection_cli_download* or all of selection_cli_creds*) + condition: selectionFindstr and (all of selection_cli_download* or all of selection_cli_creds*) falsepositives: - Administrative findstr usage level: medium