diff --git a/rules/0610-win-ms_logs_rules.xml b/rules/0610-win-ms_logs_rules.xml index 254ad6bf7..57cd87c7a 100644 --- a/rules/0610-win-ms_logs_rules.xml +++ b/rules/0610-win-ms_logs_rules.xml @@ -90,6 +90,7 @@ T1529 no_full_log + windows_log_service_stopped,