From 77aea09e0d65e1d428248b8d752ebdd3422d098b Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Wed, 25 Aug 2021 12:57:35 -0600 Subject: [PATCH] Update exchange_powershell_module_usage.yml --- .../experimental/endpoint/exchange_powershell_module_usage.yml | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/detections/experimental/endpoint/exchange_powershell_module_usage.yml b/detections/experimental/endpoint/exchange_powershell_module_usage.yml index 81af9174dd..1e4ec91080 100644 --- a/detections/experimental/endpoint/exchange_powershell_module_usage.yml +++ b/detections/experimental/endpoint/exchange_powershell_module_usage.yml @@ -4,8 +4,7 @@ version: 1 date: '2021-08-25' author: Michael Haag type: TTP -datamodel: -- Endpoint +datamodel: [] description: 'The following analytic identifies the usage of Exchange PowerShell modules that were recently used for a proof of concept related to ProxyShell. Currently, there is no active data shared or data we could re-produce relate to this part of the ProxyShell chain of exploits. \ Inherently, the usage of the modules is not malicious, but reviewing parallel processes, and user, of the session will assist with determining the intent. \