diff --git a/doc/AboutRuleCreation-English.md b/doc/AboutRuleCreation-English.md index 38b1f96e..32ab5eb7 100644 --- a/doc/AboutRuleCreation-English.md +++ b/doc/AboutRuleCreation-English.md @@ -566,7 +566,7 @@ detection: ### Or ideally something like this: ```yaml detection: - selection_basic_info: + selection_BasicInfo: Channel: Security EventID: 4648 selection_TargetUserIsComputerAccount: diff --git a/doc/AboutRuleCreation-Japanese.md b/doc/AboutRuleCreation-Japanese.md index ca1eb8d1..570caf6d 100644 --- a/doc/AboutRuleCreation-Japanese.md +++ b/doc/AboutRuleCreation-Japanese.md @@ -564,7 +564,7 @@ detection: ### 良い例: ```yaml detection: - selection_basic_info: + selection_BasicInfo: Channel: Security EventID: 4648 selection_TargetUserIsComputerAccount: