Update rules/macos/process_creation/proc_creation_macos_susp_installer_child_process.yml
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
title: Suspicious Installer Package child process
|
||||
title: Suspicious Installer Package Child Process
|
||||
id: e0cfaecd-602d-41af-988d-f6ccebb2af26
|
||||
status: experimental
|
||||
description: Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
|
||||
|
||||
Reference in New Issue
Block a user