Skip to content

Commit b18fcd4

Browse files
authored
Update tags in reconnaissance web server rule
1 parent b4b4001 commit b18fcd4

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

rules/cross-platform/reconnaissance_web_server_unusual_spike_in_error_response_codes.toml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -21,18 +21,18 @@ risk_score = 47
2121
rule_id = "6fa3abe3-9cd8-41de-951b-51ed8f710523"
2222
severity = "medium"
2323
tags = [
24-
"Domain: Single",
24+
"Domain Scope: Single",
2525
"Domain: Web",
2626
"OS: Linux",
2727
"OS: macOS",
2828
"OS: Windows",
2929
"Use Case: Threat Detection",
3030
"Tactic: Reconnaissance",
3131
"Data Source: Network Packet Capture",
32-
"Data Source: Nginx Access Logs",
33-
"Data Source: Apache Access Logs",
34-
"Data Source: Apache Tomcat Access Logs",
35-
"Data Source: IIS Access Logs",
32+
"Data Source: Nginx",
33+
"Data Source: Apache",
34+
"Data Source: Apache Tomcat",
35+
"Data Source: IIS",
3636
]
3737
timestamp_override = "event.ingested"
3838
type = "esql"

0 commit comments

Comments
 (0)