mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
6c4516730d
update_timestamp and modified testing code to always update timestamp. This will cause some issues as not all sourcetypes are supported, yet. We will work to support them all before merging these changes to develop.
13 lines
498 B
YAML
13 lines
498 B
YAML
name: Suspicious MSBuild Spawn Unit Test
|
|
tests:
|
|
- name: Suspicious MSBuild Spawn
|
|
file: endpoint/suspicious_msbuild_spawn.yml
|
|
pass_condition: '| stats count | where count > 0'
|
|
earliest_time: -24h
|
|
latest_time: now
|
|
attack_data:
|
|
- file_name: windows-sysmon.log
|
|
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log
|
|
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
|
sourcetype: xmlwineventlog
|