Update proc_creation_lnx_cve_2022_33891_spark_shell_command_injection.yml

This commit is contained in:
Nasreddine Bencherchali
2022-07-21 14:42:54 +01:00
parent a8b283ba5f
commit a46b20b78c
@@ -14,7 +14,9 @@ logsource:
detection:
selection:
ParentImage|endswith: '\bash'
CommandLine|contains: 'id -Gn `'
CommandLine|contains:
- 'id -Gn `'
- "id -Gn '"
condition: selection
falsepositives:
- Unlikely