We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 13800a7 commit 17b1fd4Copy full SHA for 17b1fd4
detections/endpoint/living_off_the_land_detection.yml
@@ -1,7 +1,7 @@
1
name: Living Off The Land Detection
2
id: 1be30d80-3a39-4df9-9102-64a467b24abc
3
-version: 5
4
-date: '2024-11-13'
+version: 6
+date: '2025-03-26'
5
author: Michael Haag, Splunk
6
status: production
7
type: Correlation
@@ -70,6 +70,6 @@ tests:
70
- name: True Positive Test
71
attack_data:
72
- data:
73
- https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
+ https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
74
source: lotl
75
sourcetype: stash
0 commit comments