From e29ebc6d921e12f790eeed45f69e2e7655b3bcc2 Mon Sep 17 00:00:00 2001 From: root Date: Thu, 5 Nov 2020 10:20:58 +0000 Subject: [PATCH] Added detection testing service results inDetect Credential Dumping through LSASS access --- .../detect_credential_dumping_through_lsass_access.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 95b2585e9c..2b9cb6fd85 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -40,3 +40,6 @@ tags: - DE.CM security_domain: endpoint asset_type: Windows + automated_detection_testing: passed + dataset: + - https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1003.001/windows-sysmon.log