Samirbous
|
6a61caa84f
|
[New Rule] Suspicious Browser Child Process (#767)
* [New Rule] Suspicious Browser Child Process
* auditbeat removed
auditbeat process execution does not log the parent process name.
* added more suspicious childproc
* added perl and php
* Update execution_initial_access_suspicious_browser_childproc.toml
* Update execution_initial_access_suspicious_browser_childproc.toml
* Update execution_initial_access_suspicious_browser_childproc.toml
* excluded noisy stuff
* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
|
2021-02-08 15:06:18 +01:00 |
|