diff --git a/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml b/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml index bd69dc768..34e136a6f 100644 --- a/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml +++ b/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml @@ -5,7 +5,6 @@ description: Detects remote RPC calls to get event log information via EVEN or E references: - https://attack.mitre.org/tactics/TA0007/ - https://github.com/zeronetworks/rpcfirewall - - https://github.com/zeronetworks/rpcfirewall - https://zeronetworks.com/blog/stopping_lateral_movement_via_the_rpc_firewall/ author: Sagie Dulce, Dekel Paz date: 2022/01/01