Files
splunk-security_content/data_sources/powershell_sip_inventory.yml
2025-01-23 10:09:09 -07:00

16 lines
510 B
YAML

name: Powershell SIP Inventory
id: 5ef5cb5d-1fa8-4567-b48f-27317662cd73
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs the inventory of System Integrity Policies (SIP) on a system retrieved
via PowerShell, including details about policy configurations and statuses.
mitre_components:
- Configuration Modification
- Host Status
- Application Log Content
- OS API Execution
source: powershell://SubjectInterfacePackage
sourcetype: PwSh:SubjectInterfacePackage
supported_TA: []