mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
small change
This commit is contained in:
@@ -2,7 +2,7 @@ name: Script Execution via WMI
|
||||
id: aa73f80d-d728-4077-b226-81ea0c8be589
|
||||
version: 3
|
||||
date: '2020-03-16'
|
||||
description: This search looks for scripts launched via WMI.
|
||||
description: This search looks for scripts launched via WMI.
|
||||
how_to_implement: You must be ingesting endpoint data that tracks process activity,
|
||||
including parent-child relationships from your endpoints to populate the Endpoint
|
||||
data model in the Processes node. The command-line arguments are mapped to the "process"
|
||||
|
||||
Reference in New Issue
Block a user