Skip to content

Commit bb01a0e

Browse files
committed
Update yml files to fix validation issues (adding source)
1 parent 87843bd commit bb01a0e

File tree

2 files changed

+4
-2
lines changed

2 files changed

+4
-2
lines changed

datasets/attack_techniques/T1553.001/atomic_red_team/macos_gatekeeper_bypass_xattr/macos_gatekeeper_bypass_xattr.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,5 @@ environment: vm
66
datasets:
77
- name: macos_gatekeeper_bypass_xattr.log
88
path: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.001/atomic_red_team/macos_gatekeeper_bypass_xattr/
9-
sourcetype: 'osquery:results'
9+
sourcetype: 'osquery:results'
10+
source: '/var/log/osquery/osqueryd.results.log'

datasets/attack_techniques/T1553.001/macos_gatekeeper_bypass_LSFileQuarantineEnabled/macos_gatekeeper_bypass_LSFileQuarantineEnabled.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,4 +6,5 @@ environment: vm
66
datasets:
77
- name: macos_gatekeeper_bypass_LSFileQuarantineEnabled.log
88
path: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1553.001/macos_gatekeeper_bypass_LSFileQuarantineEnabled/
9-
sourcetypes: 'osquery:results'
9+
sourcetypes: 'osquery:results'
10+
source: '/var/log/osquery/osqueryd.results.log'

0 commit comments

Comments
 (0)