Skip to content

Commit 55d4936

Browse files
authored
update token
1 parent c01f870 commit 55d4936

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/detect_remote_access_software_usage_registry.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ drilldown_searches:
3636
earliest_offset: $info_min_time$
3737
latest_offset: $info_max_time$
3838
- name: Investigate registry changes on $dest$
39-
search: '| from datamodel:Endpoint.Registry| search dest=$dest$ registry_path=$registry_path|s$'
39+
search: '| from datamodel:Endpoint.Registry| search dest=$dest$ registry_path=$registry_path$'
4040
earliest_offset: $info_min_time$
4141
latest_offset: $info_max_time$
4242
tags:

0 commit comments

Comments
 (0)