We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 2c9573e commit 2af5bb3Copy full SHA for 2af5bb3
1 file changed
detections/endpoint/linux_auditd_sysmon_service_stop.yml
@@ -70,6 +70,6 @@ tags:
70
tests:
71
- name: True Positive Test
72
attack_data:
73
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_auditd_service_stop/linux_auditd_service_stop.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_auditd_sysmon_service_stop/linux_auditd_sysmon_service_stop.log
74
source: auditd
75
sourcetype: auditd
0 commit comments