Update rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml

This commit is contained in:
frack113
2023-02-20 06:32:47 +01:00
committed by GitHub
parent c016748316
commit cd16dff85d
@@ -1,4 +1,4 @@
title: Suspicious Installer Package child process
title: Suspicious Installer Package Child Process
id: e0cfaecd-602d-41af-988d-f6ccebb2af26
status: experimental
description: Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters