From bbdbab700ded0d4484d909244ba3826aeefed9ca Mon Sep 17 00:00:00 2001 From: Cedric Hien Date: Sat, 17 Apr 2021 12:57:30 +0200 Subject: [PATCH] Fix invalid logsource on lnx_system_info_discovery rule --- rules/linux/lnx_system_info_discovery.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/linux/lnx_system_info_discovery.yml b/rules/linux/lnx_system_info_discovery.yml index 43f8f6563..c0742e26f 100644 --- a/rules/linux/lnx_system_info_discovery.yml +++ b/rules/linux/lnx_system_info_discovery.yml @@ -16,7 +16,7 @@ tags: --- logsource: product: linux - categories: process_creation + category: process_creation detection: selection: Image|endswith: @@ -31,7 +31,7 @@ detection: --- logsource: product: linux - categories: auditd + category: auditd detection: selection: type: 'PATH'