diff --git a/Hunting Queries/ASimProcess/imProcess_SolarWindsInventory.yaml b/Hunting Queries/ASimProcess/imProcess_SolarWindsInventory.yaml index 53e130bea7..dbc9863317 100644 --- a/Hunting Queries/ASimProcess/imProcess_SolarWindsInventory.yaml +++ b/Hunting Queries/ASimProcess/imProcess_SolarWindsInventory.yaml @@ -3,6 +3,7 @@ name: SolarWinds Inventory (Normalized Process Events) description: | 'Beyond your internal software management systems, it is possible you may not have visibility into your entire footprint of SolarWinds installations. This is intended to help use process exection information to discovery any systems that have SolarWinds processes' requiredDataConnectors: [] +tactics: - Execution relevantTechniques: - T1072