Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
8315489a072bd7ea15a6c1f7f79124f5cd6b38a0
blue-team-tools/rules/linux
T
History
Zirbo 8315489a07 Merge PR #5828 from @Zirbo - Update Shell Invocation via Env Command - Linux
update: Shell Invocation via Env Command - Linux - Switch modifier to use contains instead of endswith for better accuracy

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2026-04-28 00:31:41 +02:00
..
auditd
Merge PR #5921 from @Axel-NTT - Update BPFDoor Abnormal Process ID or Lock File Accessed
2026-04-01 13:16:52 +02:00
builtin
Merge PR #5769 from @nasbench - fix keywords rule and remove the fields field
2025-11-24 09:54:29 +01:00
file_event
Merge PR #5627 from @tsale - Filename with Embedded Base64 Commands
2025-11-24 15:33:42 +01:00
network_connection
Merge PR #5397 from @nasbench - Promote older rules status from experimental to test
2025-05-20 22:58:46 +02:00
process_creation
Merge PR #5828 from @Zirbo - Update Shell Invocation via Env Command - Linux
2026-04-28 00:31:41 +02:00
Powered by Gitea Version: 1.26.1 Page: 203ms Template: 9ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API