Merge pull request #1601 from Ronmarsiano/master

rebranding of detections
This commit is contained in:
Shain 2021-01-19 23:00:46 -08:00 коммит произвёл GitHub
Родитель ee12d6d308 1ff3674612
Коммит 326b46c43d
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23
1 изменённых файлов: 2 добавлений и 2 удалений

Просмотреть файл

@ -1,7 +1,7 @@
id: fbfbf530-506b-49a4-81ad-4030885a195c
name: Malicious web application requests linked with MDATP alerts
name: Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts
description: |
'Takes MDATP alerts where web scripts are present in the evidence and correlates with requests made to those scripts
'Takes Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts where web scripts are present in the evidence and correlates with requests made to those scripts
in the WCSIISLog to surface new alerts for potentially malicious web request activity.
The lookback for alerts is set to 1h and the lookback for W3CIISLogs is set to 7d. A sample set of popular web script extensions
has been provided in scriptExtensions that should be tailored to your environment.'