From d346de0dade63a2dbd3bbb5b676739de8d85cd82 Mon Sep 17 00:00:00 2001 From: miskoSplunk <68617976+miskoSplunk@users.noreply.github.com> Date: Fri, 26 Feb 2021 14:06:31 -0800 Subject: [PATCH] Delete ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml --- ..._process_control_via_powersploit_modules.test.yml | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml diff --git a/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml b/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml deleted file mode 100644 index 693e7a447c..0000000000 --- a/tests/endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test -tests: - - name: Illegal Service and Process Control via PowerSploit modules - file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml - pass_condition: '@count_gt(0)' - description: Test illegal service and process control detections - attack_data: - - file_name: logAllPowerSploitModulesWithOldNames.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569/logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - sourcetype: WinEventLog -