We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 2bbcdd5 commit 5158549Copy full SHA for 5158549
detections/endpoint/delete_shadowcopy_with_powershell.yml
@@ -70,6 +70,6 @@ tags:
70
tests:
71
- name: True Positive Test
72
attack_data:
73
- - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/sbl_xml.log
+ - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/powershell_script_block_logging/single_event_delete_shadowcopy.log
74
source: XmlWinEventLog:Microsoft-Windows-PowerShell/Operational
75
sourcetype: XmlWinEventLog
0 commit comments