Skip to content

Commit 2af5bb3

Browse files
committed
Sysmon service stop, not the generic one
1 parent 2c9573e commit 2af5bb3

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

detections/endpoint/linux_auditd_sysmon_service_stop.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,6 @@ tags:
7070
tests:
7171
- name: True Positive Test
7272
attack_data:
73-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_auditd_service_stop/linux_auditd_service_stop.log
73+
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1489/linux_auditd_sysmon_service_stop/linux_auditd_sysmon_service_stop.log
7474
source: auditd
7575
sourcetype: auditd

0 commit comments

Comments
 (0)