From cd16dff85dd25c0aa3479dbf485db7ff6f1a5180 Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Mon, 20 Feb 2023 06:32:47 +0100 Subject: [PATCH] Update rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml --- .../proc_creation_macos_susp_installer_child_process.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml b/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml index b10354303..dc22d6c4c 100644 --- a/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml +++ b/rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml @@ -1,4 +1,4 @@ -title: Suspicious Installer Package child process +title: Suspicious Installer Package Child Process id: e0cfaecd-602d-41af-988d-f6ccebb2af26 status: experimental description: Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters