From cfca6b19d5155c17041e511b4141cdb7982dcccb Mon Sep 17 00:00:00 2001 From: P4T12ICK Date: Mon, 29 Mar 2021 16:30:15 +0200 Subject: [PATCH] updated test file --- .../ssa___prohibited_apps_spawning_cmdprompt.test.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tests/endpoint/ssa___prohibited_apps_spawning_cmdprompt.test.yml b/tests/endpoint/ssa___prohibited_apps_spawning_cmdprompt.test.yml index d98e538bd3..e4a7ef5e02 100644 --- a/tests/endpoint/ssa___prohibited_apps_spawning_cmdprompt.test.yml +++ b/tests/endpoint/ssa___prohibited_apps_spawning_cmdprompt.test.yml @@ -5,5 +5,6 @@ tests: pass_condition: '@count_gt(0)' description: Test prohibited apps spawning cmd.exe attack_data: - - file_name: unit_test_detect_prohibited_applications_spawning_cmd_exe.json - data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/unit_test_detect_prohibited_applications_spawning_cmd_exe.json + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log + source: WinEventLog:Security \ No newline at end of file