Skip to content

Commit

Permalink
Update v3_windows_anomalous_script.json
Browse files Browse the repository at this point in the history
add the Security: Windows prefix which was missing
  • Loading branch information
randomuserid committed May 17, 2022
1 parent 62726d6 commit 927c270
Showing 1 changed file with 1 addition and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@
"bucket_span": "15m",
"detectors": [
{
"detector_description": "Detects high information content in powershell.file.script_block_text values.",
"detector_description": "Security: Windows - Detects high information content in powershell.file.script_block_text values.",
"function": "high_info_content",
"field_name": "powershell.file.script_block_text"
}
Expand Down

0 comments on commit 927c270

Please sign in to comment.