Skip to content

Commit 86fcf40

Browse files
committed
Update windows_cisco_secure_endpoint_related_service_stopped.yml
1 parent 18a70bf commit 86fcf40

File tree

1 file changed

+1
-4
lines changed

1 file changed

+1
-4
lines changed

detections/endpoint/windows_cisco_secure_endpoint_related_service_stopped.yml

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -33,12 +33,9 @@ drilldown_searches:
3333
rba:
3434
message: Cisco Secure Endpoint Service $param1$ stopped on $dest$
3535
risk_objects:
36-
- field: user
37-
type: user
38-
score: 64
3936
- field: dest
4037
type: system
41-
score: 64
38+
score: 60
4239
threat_objects:
4340
- field: param1
4441
type: service

0 commit comments

Comments
 (0)