diff --git a/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml b/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml index b10354303..dc22d6c4c 100644 --- a/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml +++ b/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml @@ -1,4 +1,4 @@ -title: Suspicious Installer Package child process +title: Suspicious Installer Package Child Process id: e0cfaecd-602d-41af-988d-f6ccebb2af26 status: experimental description: Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters