mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
6c4516730d
update_timestamp and modified testing code to always update timestamp. This will cause some issues as not all sourcetypes are supported, yet. We will work to support them all before merging these changes to develop.
21 lines
1.1 KiB
YAML
21 lines
1.1 KiB
YAML
name: Disabling FolderOptions Windows Feature Unit Test
|
|
tests:
|
|
- name: Disabling FolderOptions Windows Feature
|
|
file: endpoint/disabling_folderoptions_windows_feature.yml
|
|
pass_condition: '| stats count | where count > 0'
|
|
earliest_time: -24h
|
|
latest_time: now
|
|
attack_data:
|
|
- file_name: windows-security.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-security.log
|
|
source: WinEventLog:Security
|
|
sourcetype: WinEventLog
|
|
- file_name: windows-system.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-system.log
|
|
source: WinEventLog:System
|
|
sourcetype: WinEventLog
|
|
- file_name: windows-sysmon.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/win_app_defender_disabling/windows-sysmon.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlogE
|