Skip to content

Commit 1e6cc12

Browse files
authored
Merge pull request #3541 from jwindley/patch-2
Update detect_remote_access_software_usage_traffic.yml
2 parents dc9234a + 5cde2f9 commit 1e6cc12

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

detections/network/detect_remote_access_software_usage_traffic.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Detect Remote Access Software Usage Traffic
22
id: 885ea672-07ee-475a-879e-60d28aa5dd42
3-
version: 8
4-
date: '2025-05-02'
3+
version: 9
4+
date: '2025-05-30'
55
author: Steven Dick
66
status: production
77
type: Anomaly
@@ -16,7 +16,7 @@ description: The following analytic detects network traffic associated with know
1616
data_source:
1717
- Palo Alto Network Traffic
1818
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
19-
as lastTime values(All_Traffic.dest_port) as dest_port latest(user) as user from
19+
as lastTime values(All_Traffic.dest_port) as dest_port latest(All_Traffic.user) as user from
2020
datamodel=Network_Traffic by All_Traffic.action All_Traffic.app All_Traffic.bytes
2121
All_Traffic.bytes_in All_Traffic.bytes_out All_Traffic.dest All_Traffic.dest_ip
2222
All_Traffic.dest_port All_Traffic.dvc All_Traffic.protocol All_Traffic.protocol_version

0 commit comments

Comments
 (0)