Skip to content

Commit 51ae906

Browse files
committed
analytics_enhancement
1 parent 67844be commit 51ae906

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

detections/deprecated/suspicious_process_file_path.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
name: Suspicious Process File Path
22
id: 9be25988-ad82-11eb-a14f-acde48001122
3-
version: 6
4-
date: '2024-12-10'
3+
version: 7
4+
date: '2025-02-10'
55
author: Teoderick Contreras, Splunk
66
status: deprecated
7-
type:
7+
type: TTP
88
description: The following analytic identifies processes running from file paths not
99
typically associated with legitimate software. It leverages data from Endpoint Detection
1010
and Response (EDR) agents, focusing on specific process paths within the Endpoint

0 commit comments

Comments
 (0)