Files
sigma-rules/rules/linux
Ruben Groenewoud 27b01ac788 [New Rule] Executable Masquerading as Kernel Process (#3421)
* [New Rule] Executable Masquerading as Kernel Proc

* Bumped dates

* Added endgame support

* Added auditd_manager support

* Removed auditd_manager support for now

(cherry picked from commit 90d64f0714)
2024-02-06 09:54:53 +00:00
..