Skip to content

Commit 185a5b8

Browse files
committed
crypto_campaign
1 parent 9153947 commit 185a5b8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/windows_file_and_directory_enable_readonly_permissions.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
1515
by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.process_guid Processes.dest Processes.user
1616
| `drop_dm_object_name(Processes)`
1717
| rex field=process ":\\((?<permission>[^)]+)\\)"
18-
| eval has_write_execute=if(match(permission, "(W|GE|X|M|F)"), "true", "false")
18+
| eval has_write_execute=if(match(permission, "(W|G|X|M|F|AD|DC)"), "true", "false")
1919
| where has_write_execute="false"
2020
| `security_content_ctime(firstTime)`
2121
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)