diff --git a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml index 15aeabe4..63027a31 100644 --- a/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml +++ b/data-manipulation/encryption/create-new-key-via-cryptacquirecontext.yml @@ -5,8 +5,8 @@ rule: authors: - chuong.dong@mandiant.com scopes: - static: function - dynamic: thread + static: basic block + dynamic: call att&ck: - Defense Evasion::Obfuscated Files or Information [T1027] mbc: