Skip to content

Commit 9c5386e

Browse files
committed
Updating templated detection to work
1 parent d018384 commit 9c5386e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

contentctl/templates/detections/endpoint/anomalous_usage_of_7zip.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -53,11 +53,11 @@ tags:
5353
- name: parent_process_name
5454
type: Process
5555
role:
56-
- Parent Process
56+
- Attacker
5757
- name: process_name
5858
type: Process
5959
role:
60-
- Child Process
60+
- Attacker
6161
product:
6262
- Splunk Enterprise
6363
- Splunk Enterprise Security

0 commit comments

Comments
 (0)