Updated URLs and fixes

This commit is contained in:
mhaag-spl
2021-08-20 11:53:42 -06:00
parent b6aa47aa17
commit c302325663
4 changed files with 5 additions and 4 deletions
@@ -41,7 +41,7 @@ tags:
- Stage:Execution
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
@@ -37,7 +37,7 @@ tags:
- Stage:Execution
- Stage:Defense Evasion
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log
impact: 70
kill_chain_phases:
- Exploitation
@@ -4,7 +4,8 @@ version: 4
date: '2020-07-22'
author: David Dorsey, Splunk
type: TTP
datamodel: []
datamodel:
- Endpoint
description: This search looks for reg.exe being launched from a command prompt not
started by the user. When a user launches cmd.exe, the parent process is usually
explorer.exe. This search filters out those instances.
@@ -7,6 +7,6 @@ tests:
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog