diff --git a/rules/linux/lnx_network_service_scanning.yml b/rules/linux/lnx_network_service_scanning.yml index dbd20f8b5..b8e73ebac 100644 --- a/rules/linux/lnx_network_service_scanning.yml +++ b/rules/linux/lnx_network_service_scanning.yml @@ -8,7 +8,7 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1046/T1046.md logsource: category: process_creation - product: macos + product: linux detection: selection_1: CommandLine|contains: