Skip to content

Commit d813729

Browse files
committed
updating test section as both dataset need to be indexed together
1 parent 03b79b6 commit d813729

4 files changed

+1
-9
lines changed

detections/cloud/o365_email_password_and_payroll_compromise_behavior.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -81,8 +81,6 @@ tests:
8181
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_exchange_suspect_events.log
8282
source: o365
8383
sourcetype: o365:management:activity
84-
- name: True Positive Test
85-
attack_data:
8684
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_messagetrace_suspect_events.log
8785
source: o365_messagetrace
8886
sourcetype: o365:reporting:messagetrace

detections/cloud/o365_email_receive_and_hard_delete_takeover_behavior.yml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ search: |-
2626
| bin _time span=4hr
2727
| eval InternetMessageId = lower(InternetMessageId), user = lower(UserId), subject = Subject
2828
]
29-
| stats values(ClientIPAddress) as src, values(ClientInfoString) as http_user_agent, values(ClientProcessName) as process, values(Folder.Path) as file_path, values(Operation) as signature, values(ResultStatus) as result, values(InternetMessageId) as signature_id, count, min(mailtime) as firstTime, max(deltime) as lastTime by user,subject
29+
| stats values(ClientIPAddress) as src, values(ClientInfoString) as http_user_agent, values(Folder.Path) as file_path, values(Operation) as signature, values(ResultStatus) as result, values(InternetMessageId) as signature_id, count, min(mailtime) as firstTime, max(deltime) as lastTime by user,subject
3030
| `security_content_ctime(firstTime)`
3131
| `security_content_ctime(lastTime)`
3232
| `o365_email_receive_and_hard_delete_takeover_behavior_filter`
@@ -82,8 +82,6 @@ tests:
8282
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_exchange_suspect_events.log
8383
source: o365
8484
sourcetype: o365:management:activity
85-
- name: True Positive Test
86-
attack_data:
8785
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_messagetrace_suspect_events.log
8886
source: o365_messagetrace
8987
sourcetype: o365:reporting:messagetrace

detections/cloud/o365_email_send_and_hard_delete_exfiltration_behavior.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -84,8 +84,6 @@ tests:
8484
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_exchange_suspect_events.log
8585
source: o365
8686
sourcetype: o365:management:activity
87-
- name: True Positive Test
88-
attack_data:
8987
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_messagetrace_suspect_events.log
9088
source: o365_messagetrace
9189
sourcetype: o365:reporting:messagetrace

detections/cloud/o365_email_send_attachments_excessive_volume.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -79,8 +79,6 @@ tests:
7979
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_exchange_suspect_events.log
8080
source: o365
8181
sourcetype: o365:management:activity
82-
- name: True Positive Test
83-
attack_data:
8482
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1114/o365_suspect_email_actions/o365_messagetrace_suspect_events.log
8583
source: o365_messagetrace
8684
sourcetype: o365:reporting:messagetrace

0 commit comments

Comments
 (0)