mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Revert "Refactored security content"
This commit is contained in:
committed by
GitHub
parent
d077b90a01
commit
d78bb53baa
@@ -23,10 +23,11 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Dev Sec Ops
|
||||
asset_type: GitHub
|
||||
automated_detection_testing: passed
|
||||
confidence: 30
|
||||
context:
|
||||
- Source:Application Log
|
||||
- Source:Endpoint
|
||||
- Stage:Reconnaissance
|
||||
dataset:
|
||||
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1199/github_push_master/github_push_develop.json
|
||||
impact: 30
|
||||
@@ -39,11 +40,12 @@ tags:
|
||||
- name: commit.commit.author.email
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
- attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
- Dev Sec Ops Analytics
|
||||
required_fields:
|
||||
- _time
|
||||
risk_score: 9
|
||||
|
||||
Reference in New Issue
Block a user