We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 9b0a748 commit 10e2e11Copy full SHA for 10e2e11
detections/endpoint/windows_sql_server_xp_cmdshell_config_change.yml
@@ -73,10 +73,10 @@ tags:
73
- Splunk Enterprise Security
74
- Splunk Cloud
75
security_domain: endpoint
76
- manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing.
+ manual_test: The risk message is dynamically generated in the SPL and it needs to be manually tested for integration testing.
77
tests:
78
- name: True Positive Test
79
attack_data:
80
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.001/simulation/windows-application.log
81
source: XmlWinEventLog:Application
82
- sourcetype: XmlWinEventLog
+ sourcetype: XmlWinEventLog
0 commit comments