Skip to content

Commit c952f7b

Browse files
committed
fix: remove unnecessary tests
1 parent 6b6d458 commit c952f7b

File tree

3 files changed

+0
-18
lines changed

3 files changed

+0
-18
lines changed

detections/endpoint/windows_audit_policy_disabled_via_auditpol.yml

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,3 @@ tests:
6262
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_sysmon.log
6363
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
6464
sourcetype: XmlWinEventLog
65-
- name: True Positive Test - Security
66-
attack_data:
67-
- data:
68-
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_security.log
69-
source: XmlWinEventLog:Security
70-
sourcetype: XmlWinEventLog

detections/endpoint/windows_audit_policy_restored_via_auditpol.yml

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -62,9 +62,3 @@ tests:
6262
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_sysmon.log
6363
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
6464
sourcetype: XmlWinEventLog
65-
- name: True Positive Test - Security
66-
attack_data:
67-
- data:
68-
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_security.log
69-
source: XmlWinEventLog:Security
70-
sourcetype: XmlWinEventLog

detections/endpoint/windows_audit_policy_security_descriptor_tampering_via_auditpol.yml

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -59,9 +59,3 @@ tests:
5959
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_sysmon.log
6060
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
6161
sourcetype: XmlWinEventLog
62-
- name: True Positive Test - Security
63-
attack_data:
64-
- data:
65-
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.002/auditpol_tampering/auditpol_tampering_security.log
66-
source: XmlWinEventLog:Security
67-
sourcetype: XmlWinEventLog

0 commit comments

Comments
 (0)