diff --git a/rules/windows/process_creation/win_apt_dragonfly.yml b/rules/windows/process_creation/win_apt_dragonfly.yml index 4c1593865..78c99ce92 100755 --- a/rules/windows/process_creation/win_apt_dragonfly.yml +++ b/rules/windows/process_creation/win_apt_dragonfly.yml @@ -13,8 +13,8 @@ logsource: product: windows detection: selection: - Image: - - '*\crackmapexec.exe' + Image|endswith: + - '\crackmapexec.exe' condition: selection falsepositives: - None