Add Jamf Connect exception for macOS users enumeration rule (#1891)

* Update discovery_users_domain_built_in_commands.toml

Jamf Connect uses ldapsearch to synchronize user passwords.

* change rule update date
This commit is contained in:
Damià Poquet Femenia
2022-03-28 18:13:28 +02:00
committed by GitHub
parent 3d4eaf4caf
commit 9ad3d39a32
@@ -1,7 +1,7 @@
[metadata]
creation_date = "2021/01/12"
maturity = "production"
updated_date = "2021/03/16"
updated_date = "2022/03/28"
[rule]
author = ["Elastic"]
@@ -24,6 +24,7 @@ process where event.type in ("start", "process_started") and
"/Applications/ZoomPresence.app/Contents/MacOS/ZoomPresence",
"/Applications/Sourcetree.app/Contents/MacOS/Sourcetree",
"/Library/Application Support/JAMF/Jamf.app/Contents/MacOS/JamfDaemon.app/Contents/MacOS/JamfDaemon",
"/Applications/Jamf Connect.app/Contents/MacOS/Jamf Connect",
"/usr/local/jamf/bin/jamf"
) and
process.name : ("ldapsearch", "dsmemberutil") or