From 9ec8d40b4299ace5ff025e5b34f265e3c15027b0 Mon Sep 17 00:00:00 2001 From: jstnk9 Date: Tue, 15 Nov 2022 21:58:53 +0100 Subject: [PATCH] Update rpc_firewall_eventlog_recon.yml removed duplicated ref --- rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml b/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml index d508eb6ba..909cbb5d7 100644 --- a/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml +++ b/rules/application/rpc_firewall/rpc_firewall_eventlog_recon.yml @@ -4,7 +4,6 @@ description: Detects remote RPC calls to get event log information via EVEN or E references: - https://attack.mitre.org/tactics/TA0007/ - https://github.com/zeronetworks/rpcfirewall - - https://github.com/zeronetworks/rpcfirewall - https://zeronetworks.com/blog/stopping_lateral_movement_via_the_rpc_firewall/ status: experimental author: Sagie Dulce, Dekel Paz