Reactor - Detection - Collection

Added Collection
This commit is contained in:
Michael Haag
2018-01-31 09:29:11 -06:00
parent b010fc6205
commit dc0e511d12
+4
View File
@@ -64,6 +64,10 @@ Technique: Multiple Discovery
## Tactic: Collection
Technique: [Automated Collection](https://attack.mitre.org/wiki/Technique/T1119)
### Baseline:
filemod_count:[1 TO 1000] (process_name:cmd.exe OR process_name:powershell.exe)
## Tactic: Exfiltration
Technique: [Data Compressed](https://attack.mitre.org/wiki/Technique/T1002)