diff --git a/rules/windows/process_creation/win_susp_netsh_dll_persistence.yml b/rules/windows/process_creation/win_susp_netsh_dll_persistence.yml index 1443ecacb..885268c50 100644 --- a/rules/windows/process_creation/win_susp_netsh_dll_persistence.yml +++ b/rules/windows/process_creation/win_susp_netsh_dll_persistence.yml @@ -1,7 +1,7 @@ title: Suspicious Netsh DLL Persistence id: 56321594-9087-49d9-bf10-524fe8479452 description: Detects persitence via netsh helper -status: test +status: testing references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1128/T1128.md tags: diff --git a/tests/mapping-conditional-multi.yml b/tests/mapping-conditional-multi.yml index 1eca3e107..1959018ef 100644 --- a/tests/mapping-conditional-multi.yml +++ b/tests/mapping-conditional-multi.yml @@ -1,5 +1,5 @@ title: Contional mapping with multiple targets -status: test +status: testing description: Logpoint configuration causes conditional mapping with multiple results author: Thomas Patzke logsource: