From d667a02230bf26271efc85d1f9bded36562ef0df Mon Sep 17 00:00:00 2001 From: tccontre Date: Tue, 23 May 2023 15:46:58 +0200 Subject: [PATCH] iceid_dfir_coverage --- detections/endpoint/network_share_discovery_via_dir_command.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/network_share_discovery_via_dir_command.yml b/detections/endpoint/network_share_discovery_via_dir_command.yml index 6c16c3b8fa..4e4153caac 100644 --- a/detections/endpoint/network_share_discovery_via_dir_command.yml +++ b/detections/endpoint/network_share_discovery_via_dir_command.yml @@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk status: production type: Hunting data_source: -- - Windows Security 5140 +- Windows Security 5140 description: The following analytic identifies object access on Windows administrative SMB shares (Admin$, IPC$, C$). This represents suspicious behavior as its commonly used by tools like PsExec/PaExec and others to stage service binaries before creating and starting a Windows service on remote