Update ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml

This commit is contained in:
miskoSplunk
2020-11-18 10:10:57 -08:00
committed by GitHub
parent 7d64ec2884
commit d4688cc394
@@ -42,6 +42,11 @@ eli5: "This detection identifies use of PowerSploit modules that discover access
known_false_positives:
"None identified."
tags:
required_fields:
- _time
- process
- dest_device_id
- dest_user_id
cis20:
- CIS 16
- CIS 20