diff --git a/yml/OSBinaries/Teams.yml b/yml/OSBinaries/Teams.yml index ba85b65..2b351c5 100644 --- a/yml/OSBinaries/Teams.yml +++ b/yml/OSBinaries/Teams.yml @@ -12,7 +12,7 @@ Commands: MitreID: T1218 OperatingSystem: Windows 10, Windows 11 Full_Path: - - Path: c:\Users\username\AppData\Local\Microsoft\Teams\current\Teams.exe + - Path: %localappdata%\Microsoft\Teams\current\Teams.exe Detection: - Sigma: https://github.com/SigmaHQ/sigma/blob/43277f26fc1c81fc98fc79147b711189e901b757/rules/windows/process_creation/proc_creation_win_susp_electron_exeuction_proxy.yml Resources: