Update Analytic rule for missing technique
This commit is contained in:
Родитель
9caa8ededa
Коммит
485d5b36f3
|
@ -13,6 +13,7 @@ suppressionEnabled: false
|
|||
tactics:
|
||||
- InitialAccess
|
||||
relevantTechniques:
|
||||
- T1133
|
||||
query: |
|
||||
JamfProtect
|
||||
| where EventProduct == "Jamf Protect - Threat Events Stream"
|
||||
|
@ -68,5 +69,5 @@ entityMappings:
|
|||
fieldMappings:
|
||||
- identifier: Url
|
||||
columnName: DnsQueryName
|
||||
version: 1.0.3
|
||||
version: 1.0.4
|
||||
kind: NRT
|
Загрузка…
Ссылка в новой задаче