This commit is contained in:
mhaag-spl
2022-05-02 13:19:54 -06:00
parent e1c4b45c90
commit 25b61fe888
2 changed files with 11 additions and 5 deletions
@@ -56,7 +56,8 @@ tags:
context:
- Source:Endpoint
- Stage:Defense Evasion
dataset: []
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
impact: 80
kill_chain_phases:
- Exploitation
@@ -89,6 +90,10 @@ tags:
required_fields:
- _time
- ScriptBlockText
- Opcode
- Computer
- UserID
- EventCode
risk_score: 80
security_domain: endpoint
asset_type: Endpoint
@@ -6,7 +6,8 @@ tests:
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-powershell.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_testing/windows-powershell.log
source: WinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: WinEventLog
- file_name: sbl_xml.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: Xmlwineventlog