Files
sigma-rules/rules/macos
Samirbous dc53fc1f04 [New Rule] Persistence via Docker Shortcut Modification (#733)
* [New Rule] Persistence via Docker Shortcut Modification

* ref url decoded

* added exclusions

* Update rules/macos/persistence_docker_shortcuts_plist_modification.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* Update rules/macos/persistence_docker_shortcuts_plist_modification.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* exclude some noisy procs and conv to kql

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
2021-01-26 08:38:38 +01:00
..