diff --git a/tests/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.test.yml b/tests/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.test.yml index 2edf7f07ae..869fd675b9 100644 --- a/tests/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.test.yml +++ b/tests/endpoint/ssa___windows_system_binary_proxy_execution_compiled_html_file_decompile.test.yml @@ -6,5 +6,5 @@ tests: attack_data: - file_name: 4688_windows-security.log data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/4688_windows-security.log - source: WinEventLog:Security - update_timestamp: true \ No newline at end of file + source: XmlWinEventLog + update_timestamp: true