From ff4207b44ca0e49fc7089bea9025c415509c4c73 Mon Sep 17 00:00:00 2001 From: root Date: Tue, 10 Nov 2020 15:02:17 +0000 Subject: [PATCH] Added detection testing service results inDetect Use of cmd exe to Launch Script Interpreters --- .../detect_use_of_cmd_exe_to_launch_script_interpreters.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index d1b056bf9b..2482d00127 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -35,3 +35,6 @@ tags: - DE.CM security_domain: endpoint asset_type: Endpoint + automated_detection_testing: passed + dataset: + - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1059.003_custom_a43d29e4-3a56-4208-a0a2-44e6045f3c48/windows-sysmon.log