Update PulseConnectSecureVPN-PasswordSpray.yaml

Updating the name and description of the query.
This commit is contained in:
aprakash13 2020-09-17 11:30:07 -07:00 коммит произвёл GitHub
Родитель da7ad0bfdf
Коммит 62d305b6cd
Не найден ключ, соответствующий данной подписи
Идентификатор ключа GPG: 4AEE18F83AFDEB23
1 изменённых файлов: 2 добавлений и 3 удалений

Просмотреть файл

@ -1,8 +1,7 @@
id: 1fa1528e-f746-4794-8a41-14827f4cb798
name: PulseConnectSecure - Potential Password Spray Attempts
name: PulseConnectSecure - Large Number of Distinct Failed User Logins
description: |
'This query identifies evidence of potential password spray activity against the Pulse Secure VPN server,
by looking for failures from multiple accounts, originating from the same host within a time window'
'This query identifies evidence of failed login attempts from a large number of distinct users on a Pulse Connect Secure VPN server'
severity: Medium
requiredDataConnectors:
- connectorId: PulseConnectSecure