Skip to content

Commit 81efb27

Browse files
committed
fixed status of newly removed detection
1 parent 64aac40 commit 81efb27

4 files changed

+4
-4
lines changed

removed/detections/certutil_download_with_urlcache_and_split_arguments.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 415b4306-8bfb-11eb-85c4-acde48001122
33
version: 13
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of certutil.exe to download files

removed/detections/certutil_download_with_verifyctl_and_split_arguments.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 801ad9e4-8bfb-11eb-8b31-acde48001122
33
version: 13
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of `certutil.exe` to download

removed/detections/windows_certutil_download_with_url_argument.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944
33
version: 6
44
date: '2025-05-02'
55
author: Nasreddine Bencherchali, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of `certutil.exe` to download

removed/detections/windows_remote_access_software_hunt.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 8bd22c9f-05a2-4db1-b131-29271f28cb0a
33
version: 8
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: Hunting
88
description: This search is deprecated in favor of the new detection - Detect Remote Access Software Usage Process. The following analytic identifies the use of remote access software within
99
the environment. It leverages data from Endpoint Detection and Response (EDR) agents,

0 commit comments

Comments
 (0)