Skip to content

Commit e5bd444

Browse files
committed
update score
1 parent eae9147 commit e5bd444

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

detections/endpoint/windows_ad_privileged_object_access_activity.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ tags:
4848
- Active Directory Discovery
4949
asset_type: Endpoint
5050
confidence: 50
51-
impact: 50
51+
impact: 80
5252
message: The account $user$ accessed $object_count$ privileged AD object(s).
5353
mitre_attack_id:
5454
- T1087
@@ -73,7 +73,7 @@ tags:
7373
- EventCode
7474
- Computer
7575
- SubjectUserName
76-
risk_score: 25
76+
risk_score: 40
7777
security_domain: endpoint
7878
tests:
7979
- name: True Positive Test

0 commit comments

Comments
 (0)