diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index e76aec7810..619b9f0884 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -2,7 +2,7 @@ name: Script Execution via WMI id: aa73f80d-d728-4077-b226-81ea0c8be589 version: 3 date: '2020-03-16' -description: This search looks for scripts launched via WMI. +description: This search looks for scripts launched via WMI. how_to_implement: You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process"