From bdec923237a0622489960e70fc6a5123bbddb7bd Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Mon, 24 Oct 2022 10:09:53 -0600 Subject: [PATCH] Update suspicious_reg_exe_process.yml --- detections/endpoint/suspicious_reg_exe_process.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index 8eb801fb52..aea9e3c110 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -3,7 +3,7 @@ id: a6b3ab4e-dd77-4213-95fa-fc94701995e0 version: 4 date: '2020-07-22' author: David Dorsey, Splunk -type: TTP +type: Anomaly datamodel: - Endpoint description: This search looks for reg.exe being launched from a command prompt not