Update lnx_auditd_system_info_discovery.yml
This commit is contained in:
@@ -16,12 +16,12 @@ detection:
|
||||
- /etc/lsb-release
|
||||
- /etc/redhat-release
|
||||
- /etc/issue
|
||||
condition: 'selection or selection2'
|
||||
selection2:
|
||||
selection2:
|
||||
type: EXECVE
|
||||
a0:
|
||||
- uname
|
||||
- uptime
|
||||
condition: 'selection or selection2'
|
||||
tags:
|
||||
- attack.discovery
|
||||
- attack.t1082
|
||||
|
||||
Reference in New Issue
Block a user