From b6343d93bec4eeef182ae2bd3f2c390cf6fdee33 Mon Sep 17 00:00:00 2001 From: miskoSplunk <68617976+miskoSplunk@users.noreply.github.com> Date: Fri, 26 Feb 2021 14:04:47 -0800 Subject: [PATCH] Delete ssa___setting_credentials_via_powersploit_modules.test.yml --- ...ting_credentials_via_powersploit_modules.test.yml | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml diff --git a/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml b/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml deleted file mode 100644 index 02cc1ca781..0000000000 --- a/tests/endpoint/ssa___setting_credentials_via_powersploit_modules.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Setting Credentials via PowerSploit modules - SSA Unit test -tests: - - name: Setting Credentials via PowerSploit modules - file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml - pass_condition: '@count_gt(0)' - description: Test illegal credential setting detections - attack_data: - - file_name: logAllPowerSploitModulesWithOldNames.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - sourcetype: WinEventLog -