Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
96c0fa61761df08f3e12407c6af8cc610a2ff2b9
blue-team-tools/rules/linux
T
History
Zirbo 8315489a07 Merge PR #5828 from @Zirbo - Update Shell Invocation via Env Command - Linux
update: Shell Invocation via Env Command - Linux - Switch modifier to use contains instead of endswith for better accuracy

---------

Co-authored-by: Swachchhanda Shrawan Poudel <87493836+swachchhanda000@users.noreply.github.com>
2026-04-28 00:31:41 +02:00
..
auditd
Merge PR #5921 from @Axel-NTT - Update BPFDoor Abnormal Process ID or Lock File Accessed
2026-04-01 13:16:52 +02:00
builtin
Merge PR #5769 from @nasbench - fix keywords rule and remove the fields field
2025-11-24 09:54:29 +01:00
file_event
Merge PR #5627 from @tsale - Filename with Embedded Base64 Commands
2025-11-24 15:33:42 +01:00
network_connection
Merge PR #5397 from @nasbench - Promote older rules status from experimental to test
2025-05-20 22:58:46 +02:00
process_creation
Merge PR #5828 from @Zirbo - Update Shell Invocation via Env Command - Linux
2026-04-28 00:31:41 +02:00
Powered by Gitea Version: 1.26.1 Page: 33ms Template: 6ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API