diff --git a/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml b/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml index 748e8c552..41e31442e 100644 --- a/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml +++ b/rules/windows/registry/registry_set/registry_set_enabling_turn_off_check.yml @@ -13,7 +13,7 @@ detection: selection: EventType: SetValue TargetObject: - - 'HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics + - 'HKLM\SOFTWARE\Policies\Microsoft\Windows\ScriptedDiagnostics' Details: 'DWORD (0x00000001)' condition: selection falsepositives: