Files
splunk-security_content/tests/endpoint/ssa___agentexecutor_exe.test.yml
2022-10-18 12:48:18 -04:00

15 lines
718 B
YAML

name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path
Unit Test
tests:
- name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path
file: endpoint/ssa___agentexecutor_exe.yml
pass_condition: '@count_eq(1)'
description: ' Test Windows Rename System Utilities Agentexecutor exe LOLBAS in
Non Standard Path'
attack_data:
- file_name: dotnet_lolbin-windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/lolbas_dataset.log
source: WinEventLog:Security
file_path: ba_test_template.yml
file: endpoint/ssa___agentexecutor_exe.yml