Files
splunk-security_content/tests/T1003_002.yml
Patrick Bareiss d0aa56f92c updated test files
2020-07-29 11:00:22 +02:00

8 lines
291 B
YAML

name: Credential Dumping sam test
detections:
- name: Attempted Credential Dump From Registry via Reg exe
pass_condition: '| stats count | where count > 0'
description: Test credential dumping detections
target: attack-range-windows-domain-controller
simulation_technique: 'T1003.002'