diff --git a/rules/linux/auditd/lnx_auditd_clipboard_image_collection.yml b/rules/linux/auditd/lnx_auditd_clipboard_image_collection.yml index d9ec837b7..679063519 100644 --- a/rules/linux/auditd/lnx_auditd_clipboard_image_collection.yml +++ b/rules/linux/auditd/lnx_auditd_clipboard_image_collection.yml @@ -7,7 +7,7 @@ date: 2021/10/01 references: - https://attack.mitre.org/techniques/T1115/ - https://linux.die.net/man/1/xclip -logsources: +logsource: product: linux service: auditd detection: @@ -29,4 +29,4 @@ tags: - attack.t1115 falsepositives: - Legitimate usage of xclip tools -level: low \ No newline at end of file +level: low