diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index ceca9ef31..4e6406d3e 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1240,7 +1240,7 @@ soc: showSubtitle: true - name: HTTP description: HTTP with exe downloads - query: 'tags:http AND (file.resp_mime_types:dosexec OR file.resp_mime_types:executable) | groupby http.virtual_host' + query: 'tags:http AND file.resp_mime_types:*exec* | groupby http.virtual_host' showSubtitle: true - name: Intel description: Intel framework hits grouped by indicator