Files
sigma-rules/rules/macos
Samirbous 6a61caa84f [New Rule] Suspicious Browser Child Process (#767)
* [New Rule] Suspicious Browser Child Process

* auditbeat removed

auditbeat process execution does not log the parent process name.

* added more suspicious childproc

* added perl and php

* Update execution_initial_access_suspicious_browser_childproc.toml

* Update execution_initial_access_suspicious_browser_childproc.toml

* Update execution_initial_access_suspicious_browser_childproc.toml

* excluded noisy stuff

* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/execution_initial_access_suspicious_browser_childproc.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
2021-02-08 15:06:18 +01:00
..