mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Missed cloud
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Detect Windows DNS SIGRed via Zeek
|
||||
id: c5c622e4-d073-11ea-87d0-0242ac130003
|
||||
version: 2
|
||||
date: '2024-05-23'
|
||||
version: 3
|
||||
date: '2024-08-19'
|
||||
author: Shannon Davis, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -32,10 +32,10 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1203
|
||||
observable:
|
||||
- name: dest
|
||||
- name: flow_id
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
Reference in New Issue
Block a user