Skip to content

Commit 1e78187

Browse files
committed
crypto_campaign
1 parent 4f75199 commit 1e78187

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/windows_file_and_directory_enable_readonly_permissions.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_
1616
| `drop_dm_object_name(Processes)`
1717
| rex field=process ":\\((?<permission>[^)]+)\\)"
1818
| eval has_read_attribute=if(match(permission, "R"), "true", "false")
19-
| eval has_write_execute=if(match(permission, "(W|G|X|M|F|AD|DC|DE)"), "true", "false")
19+
| eval has_write_execute=if(match(permission, "(W|GA|X|M|F|AD|DC|DE)"), "true", "false")
2020
| where has_write_execute="false" and has_read_attribute = "true"
2121
| `security_content_ctime(firstTime)`
2222
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)