diff --git a/rules/windows/process_creation/proc_creation_win_w32tm.yml b/rules/windows/process_creation/proc_creation_win_w32tm.yml index 55c1d2255..f3881508c 100644 --- a/rules/windows/process_creation/proc_creation_win_w32tm.yml +++ b/rules/windows/process_creation/proc_creation_win_w32tm.yml @@ -24,7 +24,7 @@ detection: condition: all of selection_* falsepositives: - Legitimate use -level: medium +level: high # because unlikely legitimate use of that flag combination tags: - attack.discovery - attack.t1124