mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
20 lines
605 B
YAML
20 lines
605 B
YAML
name: Windows IIS
|
|
id: 469335b3-b6ad-49e2-bbe6-47e15c1464a7
|
|
version: 2
|
|
date: '2025-01-23'
|
|
author: Patrick Bareiss, Splunk
|
|
description: Logs changes to IIS server configuration, including updates to settings,
|
|
modules, authentication methods, and site bindings.
|
|
mitre_components:
|
|
- Service Modification
|
|
- Cloud Service Modification
|
|
- Configuration Modification
|
|
- Application Log Content
|
|
source: IIS:Configuration:Operational
|
|
sourcetype: IIS:Configuration:Operational
|
|
separator: EventID
|
|
supported_TA:
|
|
- name: Splunk Add-on for Microsoft Windows
|
|
url: https://splunkbase.splunk.com/app/742
|
|
version: 9.0.1
|