diff --git a/rules/windows/process_creation/win_task_folder_evasion.yml b/rules/windows/process_creation/win_task_folder_evasion.yml index 253824e2..dfe043a8 100644 --- a/rules/windows/process_creation/win_task_folder_evasion.yml +++ b/rules/windows/process_creation/win_task_folder_evasion.yml @@ -30,7 +30,6 @@ detection: fields: - CommandLine - ParentProcess - - CommandLine falsepositives: - Unknown level: high