Skip to content

Commit 4c1dbbb

Browse files
authored
Merge pull request #3486 from splunk/shadow_single
Update attack data - Delete ShadowCopy With PowerShell
2 parents ac5b667 + 91e97c1 commit 4c1dbbb

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/delete_shadowcopy_with_powershell.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,6 @@ tags:
7070
tests:
7171
- name: True Positive Test
7272
attack_data:
73-
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
73+
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/single_event_delete_shadowcopy.log
7474
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
7575
sourcetype: XmlWinEventLog

0 commit comments

Comments
 (0)