diff --git a/rules/windows/builtin/win_susp_wmi_login.yml b/rules/windows/builtin/win_susp_wmi_login.yml index e9627a54e..cf0bad0c5 100644 --- a/rules/windows/builtin/win_susp_wmi_login.yml +++ b/rules/windows/builtin/win_susp_wmi_login.yml @@ -13,7 +13,7 @@ logsource: detection: selection: EventID: 4624 - ProcessName: "*\\WmiPrvSE.exe" + ProcessName|endswith: "\\WmiPrvSE.exe" condition: selection falsepositives: - Monitoring tools