-
Notifications
You must be signed in to change notification settings - Fork 487
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Rule Tuning] Tuning
Direct Outbound SMB Connection
(#3485)
* tuning 'Direct Outbound SMB Connection' * removed lolbas references * reverted EQL function due to escaped characters in substring match * Update rules/windows/lateral_movement_direct_outbound_smb_connection.toml Co-authored-by: Jonhnathan <[email protected]> * Update rules/windows/lateral_movement_direct_outbound_smb_connection.toml Co-authored-by: Jonhnathan <[email protected]> * reverted internal address exclusion; adjusted rule name and description * removing min-stack * Update rules/windows/lateral_movement_direct_outbound_smb_connection.toml Co-authored-by: Jonhnathan <[email protected]> --------- Co-authored-by: Jonhnathan <[email protected]>
- Loading branch information
1 parent
74d8186
commit 3500c3d
Showing
1 changed file
with
32 additions
and
15 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters