diff --git a/detections/experimental/endpoint/exchange_powershell_module_usage.yml b/detections/experimental/endpoint/exchange_powershell_module_usage.yml index 81af9174dd..1e4ec91080 100644 --- a/detections/experimental/endpoint/exchange_powershell_module_usage.yml +++ b/detections/experimental/endpoint/exchange_powershell_module_usage.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Michael Haag type: TTP -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies the usage of Exchange PowerShell modules that were recently used for a proof of concept related to ProxyShell. Currently, there is no active data shared or data we could re-produce relate to this part of the ProxyShell chain of exploits. \ Inherently, the usage of the modules is not malicious, but reviewing parallel processes, and user, of the session will assist with determining the intent. \