From d80cee2e72b9a862afdc82eea6dbc36856b0ed1a Mon Sep 17 00:00:00 2001 From: mhaag-spl <5632822+MHaggis@users.noreply.github.com> Date: Tue, 7 Sep 2021 18:12:08 -0600 Subject: [PATCH] Update get_domaintrust_with_powershell_script_block.yml --- .../endpoint/get_domaintrust_with_powershell_script_block.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/get_domaintrust_with_powershell_script_block.yml b/detections/endpoint/get_domaintrust_with_powershell_script_block.yml index 0357309fdb..a7787fbacc 100644 --- a/detections/endpoint/get_domaintrust_with_powershell_script_block.yml +++ b/detections/endpoint/get_domaintrust_with_powershell_script_block.yml @@ -11,7 +11,7 @@ description: 'The following analytic utilizes PowerShell Script Block Logging (E During triage, review parallel processes using an EDR product or 4688 events. It will be important to understand the timeline of events around this activity. Review the entire logged PowerShell script block.' search: '`powershell` EventCode=4104 Message="*get-domaintrust*" - | stats count min(_time) as firstTime max(_time) as lastTime by Message ComputerName EventCode + | stats count min(_time) as firstTime max(_time) as lastTime by Message OpCode ComputerName User EventCode | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `get_domaintrust_with_powershell_script_block_filter`'