Update proc_creation_win_susp_advancedrun.yml

This commit is contained in:
Wagga
2022-08-29 07:56:59 +02:00
committed by GitHub
parent 11e24a6e66
commit d5724fb583
@@ -1,7 +1,7 @@
title: Suspicious AdvancedRun Execution
id: d2b749ee-4225-417e-b20e-a8d2193cbb84
status: experimental
description: Detects the execution of AdvancedRun utitlity
description: Detects the execution of AdvancedRun utility
references:
- https://twitter.com/splinter_code/status/1483815103279603714
- https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3