Update lnx_system_info_discovery.yml

This commit is contained in:
Ömer Günal
2020-10-16 10:48:36 +03:00
committed by GitHub
parent e6588c08f4
commit 68e843f0d3
+13 -1
View File
@@ -17,7 +17,19 @@ detection:
- 'hostname'
- '/etc/issue'
- 'uptime'
condition: selection
- 'lspci'
- 'dmidecode'
- 'lscpu'
- 'lsmod'
selection2:
type: 'PATH'
name:
- '/sys/class/dmi/id/bios_version'
- '/sys/class/dmi/id/product_name'
- '/sys/class/dmi/id/chassis_vendor'
- '/proc/scsi/scsi'
- '/proc/ide/hd0/model'
condition: selection or selection2
falsepositives:
- Legitimate administration activities
level: low