From 81770104efc330f9469940d543bb6fa27343a26b Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Fri, 12 Jul 2024 09:49:40 -0700 Subject: [PATCH] new public change --- .../endpoint/allow_file_and_printing_sharing_in_firewall.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml index 1a2a11b37c..c5095cb028 100644 --- a/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml +++ b/detections/endpoint/allow_file_and_printing_sharing_in_firewall.yml @@ -5,7 +5,7 @@ date: '2024-05-17' author: Teoderick Contreras, Splunk status: production type: TTP -description: The following analytic detects the modification of firewall settings +description: New public change - The following analytic detects the modification of firewall settings to allow file and printer sharing. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving 'netsh' commands that enable file and printer sharing. This activity is significant because it can