Skip to content

Commit a10fa00

Browse files
committed
Removed Observables section from last two stragglers
1 parent 8431eae commit a10fa00

File tree

2 files changed

+0
-14
lines changed

2 files changed

+0
-14
lines changed

detections/endpoint/windows_bitlockertogo_process_execution.yml

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -42,15 +42,6 @@ tags:
4242
asset_type: Endpoint
4343
mitre_attack_id:
4444
- T1218
45-
observable:
46-
- name: dest
47-
type: Endpoint
48-
role:
49-
- Victim
50-
- name: user
51-
type: User
52-
role:
53-
- Victim
5445
product:
5546
- Splunk Enterprise
5647
- Splunk Enterprise Security

detections/endpoint/windows_bitlockertogo_with_network_activity.yml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -38,11 +38,6 @@ tags:
3838
asset_type: Endpoint
3939
mitre_attack_id:
4040
- T1218
41-
observable:
42-
- name: dest
43-
type: Endpoint
44-
role:
45-
- Victim
4641
product:
4742
- Splunk Enterprise
4843
- Splunk Enterprise Security

0 commit comments

Comments
 (0)