diff --git a/anti-analysis/reference-analysis-tools-strings.yml b/anti-analysis/reference-analysis-tools-strings.yml index 22624d9b..aa30c782 100644 --- a/anti-analysis/reference-analysis-tools-strings.yml +++ b/anti-analysis/reference-analysis-tools-strings.yml @@ -24,8 +24,8 @@ rule: - string: /procmon(\.exe)?/i - string: /regmon(\.exe)?/i - string: /procexp(\.exe)?/i - - string: /ida[gqtuw]?(\.exe)?$/i - - string: /ida[gqtuw]64(\.exe)?$/i + - string: /(?