diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 8eb801fb52..aea9e3c110 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -3,7 +3,7 @@ id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 version: 4 date: '2020-07-22' author: David Dorsey, Splunk -type: TTP +type: Anomaly datamodel: - Endpoint description: This search looks for reg.exe being launched from a command prompt not