olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.12k stars 177 forks source link

Update to WMI Whitelist Macro #34

Closed billmurrin closed 4 years ago

billmurrin commented 5 years ago

I updated the WMI Whitelist macro to reflect the field names for the Whitelist. It listed process_path pipe_name (appears to have been a copy of the pipe_whitelist verbiage. These were removed and replaced with user_name wmi_consumer_name wmi_consumer_destination which should match the fields reflected in the WMI Whitelist view.

olafhartong commented 4 years ago

thanks for the PR Bill!