[Rule: Tuning] - Azure blob permission modification tagging - Correct tags (#4371)
* Remove `Data Source: Elastic Defend` tag * Update metadata --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
creation_date = "2021/09/22"
|
||||
integration = ["azure"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2025/01/11"
|
||||
|
||||
[rule]
|
||||
author = ["Austin Songer"]
|
||||
@@ -32,8 +32,7 @@ tags = [
|
||||
"Domain: Cloud",
|
||||
"Data Source: Azure",
|
||||
"Use Case: Identity and Access Audit",
|
||||
"Tactic: Defense Evasion",
|
||||
"Data Source: Elastic Defend",
|
||||
"Tactic: Defense Evasion"
|
||||
]
|
||||
timestamp_override = "event.ingested"
|
||||
type = "query"
|
||||
|
||||
Reference in New Issue
Block a user