diff --git a/yml/OtherMSBinaries/WFMFormat.yml b/yml/OtherMSBinaries/WFMFormat.yml index e08f15c..8cb874f 100644 --- a/yml/OtherMSBinaries/WFMFormat.yml +++ b/yml/OtherMSBinaries/WFMFormat.yml @@ -12,7 +12,7 @@ Commands: MitreID: T1127 OperatingSystem: Windows 10 Full_Path: - - Path: C:\there\is\no\default\installation\path + - Path: C:\there\is\no\default\installation\path\WFMFormat.exe Detection: - IOC: Child process from WFMFormat.exe Resources: