We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents ac5b667 + 91e97c1 commit 4c1dbbbCopy full SHA for 4c1dbbb
detections/endpoint/delete_shadowcopy_with_powershell.yml
@@ -70,6 +70,6 @@ tags:
70
tests:
71
- name: True Positive Test
72
attack_data:
73
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/single_event_delete_shadowcopy.log
74
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
75
sourcetype: XmlWinEventLog
0 commit comments