Update HAFNIUMUmServiceSuspiciousFile.yaml
removing the trailing dot from the "name" field
This commit is contained in:
Родитель
50835fe677
Коммит
65abd4fd30
|
@ -1,5 +1,5 @@
|
|||
id: 7d6d8a8e-b08a-4082-8dbb-d7fd2cbbc35e
|
||||
name: HAFNIUM UM Service writing suspicious file.
|
||||
name: HAFNIUM UM Service writing suspicious file
|
||||
description: |
|
||||
'This query looks for the Exchange server UM process writing suspicious files that may be indicative of webshells.
|
||||
Reference: https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/'
|
||||
|
@ -52,4 +52,4 @@ entityMappings:
|
|||
- entityType: IP
|
||||
fieldMappings:
|
||||
- identifier: Address
|
||||
columnName: IPCustomEntity
|
||||
columnName: IPCustomEntity
|
||||
|
|
Загрузка…
Ссылка в новой задаче