Skip to content

Commit

Permalink
updated test file
Browse files Browse the repository at this point in the history
  • Loading branch information
P4T12ICK committed Mar 29, 2021
1 parent eb5e776 commit ae86d61
Showing 1 changed file with 3 additions and 2 deletions.
5 changes: 3 additions & 2 deletions tests/endpoint/ssa___first_time_seen_cmd_line.test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,5 +5,6 @@ tests:
pass_condition: '@count_eq(6)'
description: Test detection of first time seen command
attack_data:
- file_name: first_time_seen_commandline.json
data: https://ssa-test-dataset.s3-us-west-2.amazonaws.com/first_time_seen_commandline.json
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/cmd_arguments/windows-security.log
source: WinEventLog:Security

0 comments on commit ae86d61

Please sign in to comment.