Update lnx_network_sniffing.yml
This commit is contained in:
@@ -23,7 +23,7 @@ detection:
|
||||
a0: 'tshark'
|
||||
a1: '-c'
|
||||
a3: '-i'
|
||||
condition: 1 of them
|
||||
condition: selection1 or selection2
|
||||
falsepositives:
|
||||
- Admin activity
|
||||
level: low
|
||||
|
||||
Reference in New Issue
Block a user