Skip to content

Commit a452372

Browse files
Update rules/network/execution_potential_rce_via_toolshell.toml
Co-authored-by: Mika Ayenson, PhD <[email protected]>
1 parent f536d6e commit a452372

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/network/execution_potential_rce_via_toolshell.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ This rule requires network traffic logs to be collected from HTTP endpoints, foc
3535
severity = "high"
3636
tags = [
3737
"Domain: Network",
38-
"Tactic: Initial Access",
38+
"Tactic: Execution",
3939
"Use Case: Threat Detection",
4040
"Data Source: Network Traffic",
4141
"Data Source: Network Traffic HTTP Logs",

0 commit comments

Comments
 (0)