mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update windows_powershell_remotesigned_file.yml
This commit is contained in:
@@ -56,6 +56,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_remotesigned/windows-powershell-xml.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_remotesigned/windows-powershell-remote-xml.log
|
||||
source: XmlWinEventLog
|
||||
sourcetype: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
|
||||
|
||||
Reference in New Issue
Block a user