Files
splunk-security_content/tests/endpoint/excessive_number_of_taskhost_processes.test.yml
pyth0n1c 6c4516730d Updated tests to remove
update_timestamp and modified
testing code to always update
timestamp.  This will cause some issues
as not all sourcetypes are supported, yet.
We will work to support them all before
merging these changes to develop.
2022-04-07 15:44:24 -07:00

13 lines
541 B
YAML

name: Excessive number of taskhost processes Unit Test
tests:
- name: Excessive number of taskhost processes
file: endpoint/excessive_number_of_taskhost_processes.yml
pass_condition: '| stats count | where count > 0'
earliest_time: -24h
latest_time: now
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/meterpreter/taskhost_processes/logExcessiveTaskHost.log
source: WinEventLog:Security
sourcetype: WinEventLog