Skip to content

Commit

Permalink
Update and rename proc_creation_win_BCP_utility.yml to win_BCP_utilit…
Browse files Browse the repository at this point in the history
…y_execution.yml
  • Loading branch information
Mahir-Ali-khan authored Aug 14, 2024
1 parent 470c3af commit 7bcd242
Showing 1 changed file with 7 additions and 3 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ references:
https://learn.microsoft.com/en-us/sql/tools/bcp-utility?view=sql-server-ver16&tabs=windows
author: MahirAli Khan (https://www.linkedin.com/in/mahiralikhan)
date: 2024-08-13
tags:
- attack.execution
- T1059.001
logsource:
category: windows
product: windows
Expand All @@ -29,6 +32,7 @@ fields:
- Creator Process Name
- New Process Name
- Process Command Line
tags:
- attack.execution
- T1059.001 # This tag corresponds to the MITRE ATT&CK technique for Command-Line Interface
falsepositives:
- Legitimate data export operations by MSSQL users
level: medium

0 comments on commit 7bcd242

Please sign in to comment.