diff --git a/rules/windows/process_creation/win_susp_winrm_execution.yml b/rules/windows/process_creation/win_susp_winrm_execution.yml index 7ec2eb9ca..218390dee 100644 --- a/rules/windows/process_creation/win_susp_winrm_execution.yml +++ b/rules/windows/process_creation/win_susp_winrm_execution.yml @@ -23,4 +23,5 @@ detection: condition: selection level: medium falsepositives: - - Legitimate use for administartive purposes. Unlikely \ No newline at end of file + - Legitimate use for administartive purposes. Unlikely +