From 3bf9acae8ccf50cd21ff159ddc3eecbb844bb630 Mon Sep 17 00:00:00 2001 From: root Date: Tue, 10 Nov 2020 08:35:10 +0000 Subject: [PATCH] Added detection testing service results inDetect Prohibited Applications Spawning cmd exe --- .../detect_prohibited_applications_spawning_cmd_exe.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 4d661af754..9f023430c9 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -36,3 +36,6 @@ tags: - DE.CM security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.003_custom_5967c616-f184-4a9d-afe4-758e0745d90e/windows-sysmon.log