diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 554c0b6c26..6931d18528 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -28,7 +28,6 @@ references: tags: analytic_story: - Ransomware - - Revil kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/allow_network_discovery_in_firewall.yml b/detections/endpoint/allow_network_discovery_in_firewall.yml index 18e94ee9e2..50bfc8ebc3 100644 --- a/detections/endpoint/allow_network_discovery_in_firewall.yml +++ b/detections/endpoint/allow_network_discovery_in_firewall.yml @@ -29,7 +29,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/disable_windows_behavior_monitoring.yml b/detections/endpoint/disable_windows_behavior_monitoring.yml index a875b904e6..eb1bab4b20 100644 --- a/detections/endpoint/disable_windows_behavior_monitoring.yml +++ b/detections/endpoint/disable_windows_behavior_monitoring.yml @@ -33,7 +33,7 @@ tags: analytic_story: - Windows Defense Evasion Tactics - Ransomware - - Revil + - Revil Ransomware automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log diff --git a/detections/endpoint/msmpeng_application_dll_side_loading.yml b/detections/endpoint/msmpeng_application_dll_side_loading.yml index 7f9a9cd8fd..310ba559c5 100644 --- a/detections/endpoint/msmpeng_application_dll_side_loading.yml +++ b/detections/endpoint/msmpeng_application_dll_side_loading.yml @@ -26,7 +26,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: diff --git a/detections/endpoint/powershell_disable_security_monitoring.yml b/detections/endpoint/powershell_disable_security_monitoring.yml index 79da1e604b..3f39baed5c 100644 --- a/detections/endpoint/powershell_disable_security_monitoring.yml +++ b/detections/endpoint/powershell_disable_security_monitoring.yml @@ -26,7 +26,7 @@ references: tags: analytic_story: - Ransomware - - Revil + - Revil Ransomware kill_chain_phases: - Exploitation mitre_attack_id: