mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
new test file
This commit is contained in:
+6
-1
@@ -4,4 +4,9 @@ detections:
|
||||
pass_condition: '| stats count | where count = 4'
|
||||
description: Test Windows Event Logs cleared (atomic red team is not yet updated)
|
||||
target: default-attack-range-windows-domain-controller
|
||||
simulation_technique: 'T1551.001'
|
||||
simulation_technique: 'T1070.001'
|
||||
attack_data:
|
||||
- file_name: windows-security.log
|
||||
data: https://attack-range-attack-data.s3-us-west-2.amazonaws.com/T1070.001/windows-security.log
|
||||
source: WinEventLog:Security
|
||||
sourcetype: WinEventLog
|
||||
|
||||
Reference in New Issue
Block a user