From e3d61d55792c508db0ca396606876900a5753fc8 Mon Sep 17 00:00:00 2001 From: Florian Roth Date: Fri, 31 Jan 2020 07:31:56 +0100 Subject: [PATCH] Missing ID --- rules/windows/builtin/win_susp_mshta_execution.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/rules/windows/builtin/win_susp_mshta_execution.yml b/rules/windows/builtin/win_susp_mshta_execution.yml index 4538c424d..c103b2259 100644 --- a/rules/windows/builtin/win_susp_mshta_execution.yml +++ b/rules/windows/builtin/win_susp_mshta_execution.yml @@ -1,4 +1,5 @@ title: MSHTA Suspicious Execution 01 +id: ee63a134-3210-4261-83cf-c33a0dbe133c status: experimental description: Detection for mshta.exe suspicious execution patterns sometimes involving file polyglotism date: 22/02/2019