We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent a642239 commit 926ca49Copy full SHA for 926ca49
detections/endpoint/detect_remote_access_software_usage_registry.yml
@@ -61,23 +61,12 @@ tags:
61
- Gozi Malware
62
- CISA AA24-241A
63
asset_type: Endpoint
64
- confidence: 50
65
- impact: 50
66
mitre_attack_id:
67
- T1219
68
product:
69
- Splunk Enterprise
70
- Splunk Enterprise Security
71
- Splunk Cloud
72
- required_fields:
73
- - _time
74
- - Registry.dest
75
- - Registry.user
76
- - Registry.registry_path
77
- - Registry.registry_value_name
78
- - Registry.registry_value_data
79
- - Registry.registry_key_name
80
- risk_score: 25
81
security_domain: endpoint
82
manual_test: This detection uses A&I lookups from Enterprise Security.
83
tests:
0 commit comments