From a2953343553444d2c6abef116dfc73798d3dd83a Mon Sep 17 00:00:00 2001 From: yugoslavskiy Date: Wed, 17 Jul 2019 07:01:58 +0300 Subject: [PATCH 1/2] win_susp_dhcp_config_failed fixed --- rules/windows/builtin/win_susp_dhcp_config_failed.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/builtin/win_susp_dhcp_config_failed.yml b/rules/windows/builtin/win_susp_dhcp_config_failed.yml index 4e08f1f9a..9ea9e2676 100644 --- a/rules/windows/builtin/win_susp_dhcp_config_failed.yml +++ b/rules/windows/builtin/win_susp_dhcp_config_failed.yml @@ -12,7 +12,7 @@ tags: author: Dimitrios Slamaris logsource: product: windows - service: dhcp + service: system detection: selection: EventID: From e8b9a6500e6cde0a382ba5c8a0860326657e832f Mon Sep 17 00:00:00 2001 From: yugoslavskiy Date: Wed, 17 Jul 2019 07:02:59 +0300 Subject: [PATCH 2/2] author string modified --- rules/windows/builtin/win_susp_dhcp_config_failed.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/windows/builtin/win_susp_dhcp_config_failed.yml b/rules/windows/builtin/win_susp_dhcp_config_failed.yml index 9ea9e2676..5309fcc8b 100644 --- a/rules/windows/builtin/win_susp_dhcp_config_failed.yml +++ b/rules/windows/builtin/win_susp_dhcp_config_failed.yml @@ -9,7 +9,7 @@ date: 2017/05/15 tags: - attack.defense_evasion - attack.t1073 -author: Dimitrios Slamaris +author: "Dimitrios Slamaris, @atc_project (fix)" logsource: product: windows service: system