601a5a1e5b
* Unusual Executable File Creation by a System Critical Process * Update defense_evasion_system_critical_proc_abnormal_file_activity.toml * Update rules/windows/defense_evasion_system_critical_proc_abnormal_file_activity.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update defense_evasion_system_critical_proc_abnormal_file_activity.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>