From d4cc96c11526f3017eb96ef97acfe791618e50af Mon Sep 17 00:00:00 2001 From: ljstella Date: Fri, 26 Jul 2024 12:11:31 -0500 Subject: [PATCH] Accidentally an extra risk object --- .../endpoint/windows_known_abused_dll_loaded_suspiciously.yml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml index 41470334e1..964d91c8a2 100644 --- a/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml +++ b/detections/endpoint/windows_known_abused_dll_loaded_suspiciously.yml @@ -51,10 +51,6 @@ tags: type: Process role: - Attacker - - name: process - type: Process - role: - - Attacker product: - Splunk Enterprise - Splunk Enterprise Security