Update lnx_system_info_discovery.yml
This commit is contained in:
@@ -19,14 +19,14 @@ logsource:
|
||||
categories: process_creation
|
||||
detection:
|
||||
selection:
|
||||
ProcessName|contains:
|
||||
- 'uname'
|
||||
- 'hostname'
|
||||
- 'uptime'
|
||||
- 'lspci'
|
||||
- 'dmidecode'
|
||||
- 'lscpu'
|
||||
- 'lsmod'
|
||||
ProcessName|endswith:
|
||||
- '/uname'
|
||||
- '/hostname'
|
||||
- '/uptime'
|
||||
- '/lspci'
|
||||
- '/dmidecode'
|
||||
- '/lscpu'
|
||||
- '/lsmod'
|
||||
condition: selection
|
||||
---
|
||||
logsource:
|
||||
|
||||
Reference in New Issue
Block a user