Fix datatypes indentations
This commit is contained in:
Родитель
6fb6ceee94
Коммит
c743164b28
|
@ -6,8 +6,8 @@ description: |
|
|||
severity: Medium
|
||||
requiredDataConnectors:
|
||||
- connectorId: TrendMicro
|
||||
- dataTypes:
|
||||
- CommonSecurityLog
|
||||
dataTypes:
|
||||
- CommonSecurityLog
|
||||
- connectorId: SecurityEvents
|
||||
dataTypes:
|
||||
- SecurityEvent
|
||||
|
|
|
@ -9,7 +9,7 @@ requiredDataConnectors:
|
|||
dataTypes:
|
||||
- DnsEvents
|
||||
- connectorId: AzureMonitor(VMInsights)
|
||||
- dataTypes:
|
||||
dataTypes:
|
||||
- VMConnection
|
||||
- connectorId: CiscoASA
|
||||
dataTypes:
|
||||
|
|
|
@ -7,7 +7,7 @@ description: |
|
|||
severity: Medium
|
||||
requiredDataConnectors:
|
||||
- connectorId: CiscoASA
|
||||
- dataTypes:
|
||||
dataTypes:
|
||||
- CommonSecurityLog
|
||||
- connectorId: AzureActiveDirectory
|
||||
dataTypes:
|
||||
|
|
|
@ -9,7 +9,7 @@ requiredDataConnectors:
|
|||
dataTypes:
|
||||
- DnsEvents
|
||||
- connectorId: AzureMonitor(VMInsights)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- VMConnection
|
||||
tactics:
|
||||
- CommandAndControl
|
||||
|
|
|
@ -12,10 +12,10 @@ requiredDataConnectors:
|
|||
dataTypes:
|
||||
- CommonSecurityLog
|
||||
- connectorId: AzureMonitor(WireData)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- WireData
|
||||
- connectorId: AzureMonitor(VMInsights)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- VMConnection
|
||||
tactics:
|
||||
- CommmandAndControl
|
||||
|
|
|
@ -23,7 +23,7 @@ requiredDataConnectors:
|
|||
dataTypes:
|
||||
- SecurityEvent
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- PrivilegeEscalation
|
||||
|
|
|
@ -14,7 +14,7 @@ requiredDataConnectors:
|
|||
dataTypes:
|
||||
- AWSCloudTrail
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- InitialAccess
|
||||
|
|
|
@ -5,7 +5,7 @@ description: |
|
|||
As File name matches can create noise, this is best as hunting query'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(VMInsights)
|
||||
- dataTypes:
|
||||
dataTypes:
|
||||
- VMConnection
|
||||
- connectorId: ThreatIntelligence
|
||||
dataTypes:
|
||||
|
|
|
@ -5,7 +5,7 @@ description: |
|
|||
As File name matches can create noise, this is best as hunting query'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(WireData)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- WireData
|
||||
- connectorId: ThreatIntelligence
|
||||
dataTypes:
|
||||
|
|
|
@ -8,7 +8,7 @@ description: |
|
|||
Win32 Status code mapping - https://msdn.microsoft.com/en-us/library/cc231199.aspx'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- InitialAccess
|
||||
|
|
|
@ -8,7 +8,7 @@ description: |
|
|||
There could be some web sites like wikis with articles on os commands and pages that include the os //commands in the URLs that might cause FP.'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- Persistence
|
||||
|
|
|
@ -10,7 +10,7 @@ description: |
|
|||
Win32 Status code mapping - https://msdn.microsoft.com/en-us/library/cc231199.aspx'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- CredentialAccess
|
||||
|
|
|
@ -6,7 +6,7 @@ description: |
|
|||
The initial goal of this detection is to flag these events when they occur and give an opportunity to review the data and filter out authorized activity.'
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- InitialAccess
|
||||
|
|
|
@ -5,7 +5,7 @@ description: |
|
|||
severity: Low
|
||||
requiredDataConnectors:
|
||||
- connectorId: AzureMonitor(IIS)
|
||||
dataTypes:
|
||||
dataTypes:
|
||||
- W3CIISLog
|
||||
tactics:
|
||||
- InitialAccess
|
||||
|
|
Загрузка…
Ссылка в новой задаче