From 10941b11152f3f07694ae3cabea924373f23c51c Mon Sep 17 00:00:00 2001 From: Daniel Stepanic <57736958+dstepanic@users.noreply.github.com> Date: Wed, 24 Apr 2024 14:02:04 -0500 Subject: [PATCH] Update self-delete-using-alternate-data-streams.yml --- .../self-deletion/self-delete-using-alternate-data-streams.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml b/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml index 9ad68965..78b77d54 100644 --- a/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml +++ b/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml @@ -48,6 +48,6 @@ rule: - number: 0x10000 = DELETE - and: - instruction: - - description: Uses arithmetic to return FILE_INFORMATION_CLASS (FileRenameInfo) + - description: Uses arithmetic to return FILE_INFORMATION_CLASS (FileRenameInfo) - mnemonic: lea - offset: -0x1D