mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
16 lines
565 B
YAML
16 lines
565 B
YAML
name: Powershell SIP Inventory
|
|
id: 5ef5cb5d-1fa8-4567-b48f-27317662cd73
|
|
version: 3
|
|
creation_date: '2024-05-22'
|
|
modification_date: '2026-05-13'
|
|
author: Patrick Bareiss, Splunk
|
|
description: Logs the inventory of System Integrity Policies (SIP) on a system retrieved via PowerShell, including details about policy configurations and statuses.
|
|
mitre_components:
|
|
- Configuration Modification
|
|
- Host Status
|
|
- Application Log Content
|
|
- OS API Execution
|
|
source: powershell://SubjectInterfacePackage
|
|
sourcetype: PwSh:SubjectInterfacePackage
|
|
supported_TA: []
|