diff --git a/rules/windows/discovery_process_discovery_via_tasklist_command.toml b/rules/_deprecated/discovery_process_discovery_via_tasklist_command.toml similarity index 93% rename from rules/windows/discovery_process_discovery_via_tasklist_command.toml rename to rules/_deprecated/discovery_process_discovery_via_tasklist_command.toml index 06d24ad81..7225bf0c5 100644 --- a/rules/windows/discovery_process_discovery_via_tasklist_command.toml +++ b/rules/_deprecated/discovery_process_discovery_via_tasklist_command.toml @@ -1,7 +1,8 @@ [metadata] creation_date = "2020/02/18" -maturity = "production" -updated_date = "2021/03/03" +deprecation_date = "2021/04/15" +maturity = "deprecated" +updated_date = "2021/04/15" [rule] author = ["Elastic"] @@ -42,4 +43,3 @@ reference = "https://attack.mitre.org/techniques/T1057/" id = "TA0007" name = "Discovery" reference = "https://attack.mitre.org/tactics/TA0007/" -