diff --git a/Osquery/200200-osquery.xml b/Osquery/200200-osquery.xml index a79c210..f5bfe75 100644 --- a/Osquery/200200-osquery.xml +++ b/Osquery/200200-osquery.xml @@ -617,7 +617,7 @@ 200223 - users|w|who + ^users$|^w$|^who$ Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. no_full_log