5bbe3dec9b
changes were completed to remove ( * ) and stay within rule creation guide:
- Image|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
WMIcommand|contains: 'Win32_Process\:\:Create'