Files
splunk-security_content/lookups/splunk_risky_command.yml
pyth0n1c 732aec3f95 Delete detection and migrate
logic and documentation to risky
command lookup file. Update macro
to point to new risky command csv.
Fiox some opservables.
2023-09-28 14:51:28 -07:00

8 lines
256 B
YAML

description: A list of Risky Splunk Command that are candidates for abuse
filename: splunk_risky_command_20231003.csv
name: splunk_risky_command
default_match: 'false'
match_type: WILDCARD(splunk_risky_command)
min_matches: 1
case_sensitive_match: 'false'