diff --git a/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml b/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml index 79ce72384..24bbed6fd 100644 --- a/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml +++ b/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml @@ -1,7 +1,7 @@ title: Suspicious AdvancedRun Execution id: d2b749ee-4225-417e-b20e-a8d2193cbb84 status: experimental -description: Detects the execution of AdvancedRun utitlity +description: Detects the execution of AdvancedRun utility references: - https://twitter.com/splinter_code/status/1483815103279603714 - https://medium.com/s2wblog/analysis-of-destructive-malware-whispergate-targeting-ukraine-9d5d158f19f3