diff --git a/detections/network/cisco_secure_firewall___high_volume_of_intrusion_events_per_host.yml b/detections/network/cisco_secure_firewall___high_volume_of_intrusion_events_per_host.yml index c1ff194d38..d3e1e344bd 100644 --- a/detections/network/cisco_secure_firewall___high_volume_of_intrusion_events_per_host.yml +++ b/detections/network/cisco_secure_firewall___high_volume_of_intrusion_events_per_host.yml @@ -58,9 +58,9 @@ analytic_story: - Cisco Secure Firewall Threat Defense Analytics asset_type: Network mitre_attack_id: - - T1059 # Command and Scripting Interpreter - - T1071 # Application Layer Protocol - - T1595.002 # Active Scanning: Vulnerability Scanning + - T1059 # Command and Scripting Interpreter + - T1071 # Application Layer Protocol + - T1595.002 # Active Scanning: Vulnerability Scanning product: - Splunk Enterprise - Splunk Cloud