dc53fc1f04
* [New Rule] Persistence via Docker Shortcut Modification * ref url decoded * added exclusions * Update rules/macos/persistence_docker_shortcuts_plist_modification.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/macos/persistence_docker_shortcuts_plist_modification.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * exclude some noisy procs and conv to kql Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>