diff --git a/nursery/get-workstation-config.yml b/nursery/get-workstation-config.yml new file mode 100644 index 000000000..87e14a60a --- /dev/null +++ b/nursery/get-workstation-config.yml @@ -0,0 +1,18 @@ +rule: + meta: + name: get workstation config + namespace: network/workstation + authors: + - kevross33/Kevin Ross + scopes: + static: function + dynamic: span of calls + att&ck: + - Discovery::System Network Configuration Discovery [T1016] + examples: + - f5fca1b178af87bd48c7ea9e3f2c957b + features: + - and: + - string: /net/i + - string: /config/i + - string: /workstation/i