mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update ssa___assess_credential_strength_via_dsinternals_modules.yml
This commit is contained in:
@@ -25,12 +25,12 @@ search: '| from read_ssa_enriched_events()
|
||||
eli5: "This detection identifies use of DSInternals modules which assess password strength."
|
||||
known_false_positives:
|
||||
"None identified."
|
||||
required_fields:
|
||||
tags:
|
||||
required_fields:
|
||||
- _time
|
||||
- process
|
||||
- dest_device_id
|
||||
- dest_user_id
|
||||
tags:
|
||||
cis20:
|
||||
- CIS 16
|
||||
- CIS 20
|
||||
|
||||
Reference in New Issue
Block a user