Update proc_creation_lnx_susp_history_delete.yml
This commit is contained in:
@@ -13,7 +13,9 @@ detection:
|
||||
selection:
|
||||
Image|endswith: '/rm'
|
||||
selection_history:
|
||||
- CommandLine|contains: '/.bash_history'
|
||||
- CommandLine|contains:
|
||||
- '/.bash_history'
|
||||
- '/.zsh_history
|
||||
- CommandLine|endswith: '_history'
|
||||
condition: all of selection*
|
||||
falsepositives:
|
||||
|
||||
Reference in New Issue
Block a user