From 15e747d27e6a8003cb33a4de4e5ca7ce06aa41b2 Mon Sep 17 00:00:00 2001 From: root Date: Fri, 20 Nov 2020 14:56:44 +0000 Subject: [PATCH] Added detection testing service results inMalicious PowerShell Process - Execution Policy Bypass --- .../malicious_powershell_process___execution_policy_bypass.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 3e13290e9b..1471252063 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -41,3 +41,6 @@ tags: - PR.IP security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.001/windows-sysmon.log