Files
sigma-rules/rules/cross-platform
Samirbous 0dcd5e82c8 [Rule Tuning] Suspicious JAR Child Process (#1657)
* [Rule Tuning] Suspicious JAR Child Process
Expand rule coverage by removing the process.args containing a jar file requirement which may help detect also exploitation attempt via command injection vulnerabilities on server apps running JAVA.
* Update rules/cross-platform/execution_suspicious_jar_child_process.toml

(cherry picked from commit 410d4e5929)
2021-12-11 01:06:29 +00:00
..