From 0806e4ccd28271f628e5579965be1ec6dffbf5ff Mon Sep 17 00:00:00 2001 From: Sittikorn S <61369934+BlackB0lt@users.noreply.github.com> Date: Fri, 10 Sep 2021 11:30:51 +0700 Subject: [PATCH] Update web_cve_2021_40539_manageengine_adselfservice_exploit.yml --- .../web_cve_2021_40539_manageengine_adselfservice_exploit.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/rules/web/web_cve_2021_40539_manageengine_adselfservice_exploit.yml b/rules/web/web_cve_2021_40539_manageengine_adselfservice_exploit.yml index 1f049dbf4..a0ff44c94 100644 --- a/rules/web/web_cve_2021_40539_manageengine_adselfservice_exploit.yml +++ b/rules/web/web_cve_2021_40539_manageengine_adselfservice_exploit.yml @@ -11,6 +11,7 @@ tags: - attack.initial_access - attack.t1190 logsource: + product: zoho_manageengine category: webserver definition: 'Must be collect log from \ManageEngine\ADSelfService Plus\logs' detection: