From 6cd83a232d31d41dcbe979a5e868bc5dfa540b97 Mon Sep 17 00:00:00 2001 From: Nasreddine Bencherchali <8741929+nasbench@users.noreply.github.com> Date: Tue, 5 Jul 2022 19:43:58 +0100 Subject: [PATCH] Update file_create_lnx_persistence_sudoers_files.yml --- .../file_create/file_create_lnx_persistence_sudoers_files.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/linux/file_create/file_create_lnx_persistence_sudoers_files.yml b/rules/linux/file_create/file_create_lnx_persistence_sudoers_files.yml index be7e1f5d9..d7e0270c2 100644 --- a/rules/linux/file_create/file_create_lnx_persistence_sudoers_files.yml +++ b/rules/linux/file_create/file_create_lnx_persistence_sudoers_files.yml @@ -14,7 +14,7 @@ detection: TargetFilename|startswith: '/etc/sudoers.d/' condition: selection falsepositives: - - Creation of legitimate files in sudoers.d folder par of administrator work + - Creation of legitimate files in sudoers.d folder part of administrator work level: medium tags: - attack.persistence