Skip to content

Commit 07c0ba7

Browse files
committed
version revert
1 parent 61e4add commit 07c0ba7

File tree

39 files changed

+39
-39
lines changed

39 files changed

+39
-39
lines changed

detections/endpoint/any_powershell_downloadfile.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Any Powershell DownloadFile
22
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
3-
version: '10'
3+
version: 9
44
date: '2025-01-27'
55
author: Michael Haag, Splunk
66
status: production

detections/endpoint/detect_renamed_psexec.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Detect Renamed PSExec
22
id: 683e6196-b8e8-11eb-9a79-acde48001122
3-
version: '11'
3+
version: 10
44
date: '2025-01-27'
55
author: Michael Haag, Splunk, Alex Oberkircher, Github Community
66
status: production

detections/endpoint/detect_renamed_winrar.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Detect Renamed WinRAR
22
id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122
3-
version: '9'
3+
version: 8
44
date: '2025-01-27'
55
author: Michael Haag, Splunk
66
status: production

detections/endpoint/executables_or_script_creation_in_suspicious_path.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Executables Or Script Creation In Suspicious Path
22
id: a7e3f0f0-ae42-11eb-b245-acde48001122
3-
version: '11'
3+
version: 10
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

detections/endpoint/linux_auditd_file_permission_modification_via_chmod.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Auditd File Permission Modification Via Chmod
22
id: 5f1d2ea7-eec0-4790-8b24-6875312ad492
3-
version: '7'
3+
version: 6
44
date: '2025-01-27'
55
author: "Teoderick Contreras, Splunk, Ivar Nyg\xE5rd"
66
status: production

detections/endpoint/linux_auditd_nopasswd_entry_in_sudoers_file.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Auditd Nopasswd Entry In Sudoers File
22
id: 651df959-ad17-4b73-a323-90cb96d5fa1b
3-
version: '5'
3+
version: 4
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

detections/endpoint/linux_auditd_possible_access_to_credential_files.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Auditd Possible Access To Credential Files
22
id: 0419cb7a-57ea-467b-974f-77c303dfe2a3
3-
version: '5'
3+
version: 4
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

detections/endpoint/linux_auditd_possible_access_to_sudoers_file.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Auditd Possible Access To Sudoers File
22
id: 8be88f46-f7e8-4ae6-b15e-cf1b13392834
3-
version: '5'
3+
version: 4
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

detections/endpoint/linux_auditd_preload_hijack_library_calls.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Auditd Preload Hijack Library Calls
22
id: 35c50572-a70b-452f-afa9-bebdf3c3ce36
3-
version: '5'
3+
version: 4
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

detections/endpoint/linux_common_process_for_elevation_control.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
name: Linux Common Process For Elevation Control
22
id: 66ab15c0-63d0-11ec-9e70-acde48001122
3-
version: '6'
3+
version: 5
44
date: '2025-01-27'
55
author: Teoderick Contreras, Splunk
66
status: production

0 commit comments

Comments
 (0)