Skip to content

Commit

Permalink
fix for flaky integration tests (#167) (#181)
Browse files Browse the repository at this point in the history
Signed-off-by: Subhobrata Dey <sbcd90@gmail.com>
  • Loading branch information
opensearch-trigger-bot[bot] committed Dec 12, 2022
1 parent 2c21de6 commit 10034e0
Show file tree
Hide file tree
Showing 5 changed files with 5 additions and 5 deletions.
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
title: Regsvr32 Network Activity
id: 36e037c4-c228-4866-b6a3-48eb292b9955
id: 36a037c4-c228-4866-b6a3-48eb292b9955
related:
- id: c7e91a02-d771-4a6d-a700-42587e0b1095
type: derived
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
title: Regsvr32 Network Activity
id: c7e91a02-d771-4a6d-a700-42587e0b1095
id: c6e91a02-d771-4a6d-a700-42587e0b1095
description: Detects network connections and DNS queries initiated by Regsvr32.exe
references:
- https://pentestlab.blog/2017/05/11/applocker-bypass-regsvr32/
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
title: Regsvr32 Command Line Without DLL
id: 50919691-7302-437f-8e10-1fe088afa145
id: 5a919691-7302-437f-8e10-1fe088afa145
status: experimental
description: Detects a regsvr.exe execution that doesn't contain a DLL in the command line
author: Florian Roth
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
title: System File Execution Location Anomaly
id: e4a6b256-3e47-40fc-89d2-7a477edd6915
id: e5a6b256-3e47-40fc-89d2-7a477edd6915
status: experimental
description: Detects a Windows program executable started in a suspicious folder
references:
Expand Down
2 changes: 1 addition & 1 deletion src/main/resources/rules/test_windows/win_sample_rule.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
title: QuarksPwDump Clearing Access History
id: 06724a9a-52fc-11ed-bdc3-0242ac120002
id: 06724b9a-52fc-11ed-bdc3-0242ac120002
status: experimental
description: Detects QuarksPwDump clearing access history in hive
author: Florian Roth
Expand Down

0 comments on commit 10034e0

Please sign in to comment.