mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
adding asset_type
This commit is contained in:
@@ -32,7 +32,7 @@ tags:
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.001/impacket/windows-security.log
|
||||
kill_chain_phases:
|
||||
- Privilege Escalation
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1558
|
||||
- T1558.001
|
||||
@@ -55,9 +55,10 @@ tags:
|
||||
context:
|
||||
- Source:Endpoint
|
||||
- Stage:Privilege Escalation
|
||||
message:
|
||||
message: A Kerberos Service TTicket request with RC4 encryption was requested from $Client_Address$
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
- Victim
|
||||
asset_type: Endpoint
|
||||
Reference in New Issue
Block a user