Skip to content

Commit cae26d3

Browse files
JV0812kimsauce
andauthored
Update docs/integrations/security-threat-detection/threat-intel-quick-analysis.md
Co-authored-by: Kim (Sumo Logic) <[email protected]>
1 parent 64e3a78 commit cae26d3

File tree

1 file changed

+7
-7
lines changed

1 file changed

+7
-7
lines changed

docs/integrations/security-threat-detection/threat-intel-quick-analysis.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -375,13 +375,13 @@ Once an indicator has been marked with a malicious confidence level, it continue
375375
**Data Type:** string<br/>
376376
**Description:** The point in the kill chain at which an indicator is associated. The kill chain list is also represented under the labels list in the JSON data structure.<br/>
377377
**Values:**
378-
* reconnaissance—This indicator is associated with the research, identification, and selection of targets by a malicious actor.
379-
* weaponization—This indicator is associated with assisting a malicious actor create malicious content.
380-
* delivery—This indicator is associated with the delivery of an exploit or malicious payload.
381-
* exploitation—This indicator is associated with the exploitation of a target system or environment.
382-
* installation—This indicator is associated with the installation or infection of a target system with a remote access tool or other tool allowing for persistence in the target environment.
383-
* c2 (Command and Control)—This indicator is associated with malicious actor command and control.
384-
* actionOnObjectives—This indicator is associated with a malicious actor's desired effects and goals.
378+
* reconnaissance—This indicator is associated with the research, identification, and selection of targets by a malicious actor.
379+
* weaponization—This indicator is associated with assisting a malicious actor create malicious content.
380+
* delivery—This indicator is associated with the delivery of an exploit or malicious payload.
381+
* exploitation—This indicator is associated with the exploitation of a target system or environment.
382+
* installation—This indicator is associated with the installation or infection of a target system with a remote access tool or other tool allowing for persistence in the target environment.
383+
* c2 (Command and Control)—This indicator is associated with malicious actor command and control.
384+
* actionOnObjectives—This indicator is associated with a malicious actor's desired effects and goals.
385385
386386
---
387387
#### `labels`

0 commit comments

Comments
 (0)