[Security Content] Include "Data Source: Elastic Defend" tag (#3002)
* win folder
* Other folders
* Update test_all_rules.py
* .
* updated missing elastic defend tags
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
(cherry picked from commit 4233fef238)
This commit is contained in:
committed by
github-actions[bot]
parent
4bb0cdc3f3
commit
063386829c
@@ -23,7 +23,7 @@ name = "Potential Code Execution via Postgresql"
|
||||
risk_score = 47
|
||||
rule_id = "2a692072-d78d-42f3-a48a-775677d79c4e"
|
||||
severity = "medium"
|
||||
tags = ["Domain: Endpoint", "OS: Linux", "Use Case: Threat Detection", "Tactic: Execution", "Data Source: Elastic Endgame"]
|
||||
tags = ["Domain: Endpoint", "OS: Linux", "Use Case: Threat Detection", "Tactic: Execution", "Data Source: Elastic Endgame", "Data Source: Elastic Defend"]
|
||||
type = "eql"
|
||||
|
||||
query = '''
|
||||
|
||||
Reference in New Issue
Block a user