From a2a1b203355da71caac0a40a285eb67a0cde4fa0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=C3=96mer=20G=C3=BCnal?= Date: Wed, 21 Oct 2020 21:40:46 +0300 Subject: [PATCH] Update lnx_process_discovery.yml --- rules/linux/lnx_process_discovery.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/linux/lnx_process_discovery.yml b/rules/linux/lnx_process_discovery.yml index 5ca621ead..a6bf0eec1 100644 --- a/rules/linux/lnx_process_discovery.yml +++ b/rules/linux/lnx_process_discovery.yml @@ -10,7 +10,7 @@ logsource: product: linux detection: selection: - - CommandLine|contains: + - ProcessName|contains: - 'ps ' - 'top' condition: selection