Skip to content

Fix regsvr32 typo in ADS process detection#4099

Open
srkyn wants to merge 1 commit into
splunk:developfrom
srkyn:codex/fix-regsvr32-ads-detection
Open

Fix regsvr32 typo in ADS process detection#4099
srkyn wants to merge 1 commit into
splunk:developfrom
srkyn:codex/fix-regsvr32-ads-detection

Conversation

@srkyn
Copy link
Copy Markdown

@srkyn srkyn commented May 22, 2026

Summary

  • Corrects regscr32.exe to regsvr32.exe in the Windows Alternate DataStream - Process Execution analytic.

Why

Validation

  • Confirmed the detection file no longer contains regscr32.exe.
  • Confirmed regsvr32.exe is present in the process-name list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Typo in windows_alternate_datastream___process_execution.yml - regscr32.exe should be regsvr32.exe

1 participant