Nasreddine Bencherchali
0d2ddb4a9b
fix: small selection fix for clarity
2022-12-27 16:23:09 +01:00
Nasreddine Bencherchali
256d6a839e
fix: update condition
...
Co-authored-by: frack113 <62423083+frack113@users.noreply.github.com >
2022-12-27 16:13:56 +01:00
Nasreddine Bencherchali
281dc11fc5
fix: remove correlation
2022-12-27 15:31:51 +01:00
BlueTeamOps
1d8256fa69
Update lnx_auditd_debugfs_usage.yml
2022-12-25 09:47:19 +11:00
BlueTeamOps
81d8d1a5a7
replaced timeframe with timespan
2022-12-25 08:10:03 +11:00
BlueTeamOps
976d994cee
Updated to include additional tools
...
Expanded the list of Linux tools that may be used to obtain volume meta info and also included the auditd.
Removed specific switches for tools as those tools and debugfs exec within that time period will be rare.
2022-12-25 07:57:18 +11:00
BlueTeamOps
de84fbcd62
lnx_auditd_debugfs_usage.yml
2022-12-24 23:41:20 +11:00