mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -38,7 +38,7 @@ tags:
|
||||
- name: file_name
|
||||
type: File Name
|
||||
role:
|
||||
- Victim
|
||||
- Victim
|
||||
- name: signature
|
||||
type: Other
|
||||
role:
|
||||
@@ -63,4 +63,4 @@ tests:
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
source: o365
|
||||
|
||||
@@ -48,7 +48,7 @@ tags:
|
||||
- name: src_user
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
- Attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -67,4 +67,4 @@ tests:
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
source: o365
|
||||
|
||||
Reference in New Issue
Block a user