diff --git a/rules/generic/PyInstaller.yar b/rules/generic/PyInstaller.yar index 37e4c06..3be904e 100644 --- a/rules/generic/PyInstaller.yar +++ b/rules/generic/PyInstaller.yar @@ -14,7 +14,7 @@ rule PyInstaller sharing = "TLP:WHITE" source = "BARTBLAZE" author = "@bartblaze" - description = "Identifies executable converted using PyInstaller." + description = "Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious." category = "INFO" strings: