Update lnx_auditd_masquerading_crond.yml

This commit is contained in:
yugoslavskiy
2019-11-04 22:14:10 +03:00
committed by GitHub
parent 0d5489bbb0
commit 8b2216e94e
@@ -2,6 +2,7 @@ title: Masquerading as Linux crond process
status: experimental
description: Masquerading occurs when the name or location of an executable, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. Several different variations of this technique have been observed.
author: Timur Zinniatullin, oscd.community
date: 2019/10/21
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1036/T1036.yaml
logsource: