diff --git a/yml/OSBinaries/Hh.yml b/yml/OSBinaries/Hh.yml index fcaf79f..a48b970 100644 --- a/yml/OSBinaries/Hh.yml +++ b/yml/OSBinaries/Hh.yml @@ -19,8 +19,7 @@ Commands: MitreID: T1218.001 OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10 Full_Path: - - Path: C:\Windows\System32\hh.exe - - Path: C:\Windows\SysWOW64\hh.exe + - Path: C:\Windows\hh.exe Code_Sample: - Code: Detection: