diff --git a/rules/windows/registry_event/sysmon_reg_silentprocessexit.yml b/rules/windows/registry_event/sysmon_reg_silentprocessexit.yml index 599ae9188..fe6b5f5a5 100644 --- a/rules/windows/registry_event/sysmon_reg_silentprocessexit.yml +++ b/rules/windows/registry_event/sysmon_reg_silentprocessexit.yml @@ -15,7 +15,7 @@ logsource: detection: selection: TargetObject|contains: 'Microsoft\Windows NT\CurrentVersion\SilentProcessExit' - Details|contain: 'MonitorProcess' + Details|contains: 'MonitorProcess' EventType: - SetValue - CreateValue