diff --git a/rules/windows/builtin/win_susp_mshta_execution.yml b/rules/windows/builtin/win_susp_mshta_execution.yml index 4538c424d..c103b2259 100644 --- a/rules/windows/builtin/win_susp_mshta_execution.yml +++ b/rules/windows/builtin/win_susp_mshta_execution.yml @@ -1,4 +1,5 @@ title: MSHTA Suspicious Execution 01 +id: ee63a134-3210-4261-83cf-c33a0dbe133c status: experimental description: Detection for mshta.exe suspicious execution patterns sometimes involving file polyglotism date: 22/02/2019