Skip to content

Commit 45f804c

Browse files
author
Nic
authored
[SIEM] Detection Fix typo in Adobe Hijack Persistence rule (#58804)
Fixes #58803
1 parent 5b532ff commit 45f804c

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

x-pack/legacy/plugins/siem/server/lib/detection_engine/rules/prepackaged_rules/eql_adobe_hijack_persistence.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"language": "kuery",
77
"max_signals": 100,
88
"name": "Adobe Hijack Persistence",
9-
"query": "file.path:(\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\" or \"C:\\Program Files\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\") and event.action:\"File created (rule: FileCreate)\" and not process.name:msiexeec.exe",
9+
"query": "file.path:(\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\" or \"C:\\Program Files\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\") and event.action:\"File created (rule: FileCreate)\" and not process.name:msiexec.exe",
1010
"risk_score": 21,
1111
"rule_id": "2bf78aa2-9c56-48de-b139-f169bf99cf86",
1212
"severity": "low",
@@ -32,5 +32,5 @@
3232
}
3333
],
3434
"type": "query",
35-
"version": 1
35+
"version": 2
3636
}

0 commit comments

Comments
 (0)