Update lnx_install_root_certificate.yml
This commit is contained in:
@@ -14,12 +14,14 @@ detection:
|
||||
- CommandLine|contains|all:
|
||||
- 'mv '
|
||||
- '/usr/local/share/ca-certificates'
|
||||
- 'update-ca-certificates'
|
||||
selection2:
|
||||
- ProcessName|contains:
|
||||
- 'update-ca-certificates'
|
||||
selection3:
|
||||
- CommandLine|contains|all:
|
||||
- 'cp '
|
||||
- 'rootCA.crt'
|
||||
- 'update-ca-trust'
|
||||
condition: selection or selection2
|
||||
condition: (selection and selection2) or selection3
|
||||
falsepositives:
|
||||
- Legitimate administration activities
|
||||
|
||||
Reference in New Issue
Block a user