Skip to content

Commit 926ca49

Browse files
committed
remove extra fields
1 parent a642239 commit 926ca49

File tree

1 file changed

+0
-11
lines changed

1 file changed

+0
-11
lines changed

detections/endpoint/detect_remote_access_software_usage_registry.yml

Lines changed: 0 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -61,23 +61,12 @@ tags:
6161
- Gozi Malware
6262
- CISA AA24-241A
6363
asset_type: Endpoint
64-
confidence: 50
65-
impact: 50
6664
mitre_attack_id:
6765
- T1219
6866
product:
6967
- Splunk Enterprise
7068
- Splunk Enterprise Security
7169
- Splunk Cloud
72-
required_fields:
73-
- _time
74-
- Registry.dest
75-
- Registry.user
76-
- Registry.registry_path
77-
- Registry.registry_value_name
78-
- Registry.registry_value_data
79-
- Registry.registry_key_name
80-
risk_score: 25
8170
security_domain: endpoint
8271
manual_test: This detection uses A&I lookups from Enterprise Security.
8372
tests:

0 commit comments

Comments
 (0)