acff6a3a5d
* [New Rule] 2 Rules for Persistence via Emond * removed auditbeat index process.parent.name not captured * Update persistence_emond_rules_process_execution.toml * Update rules/macos/persistence_emond_rules_file_creation.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/macos/persistence_emond_rules_process_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/macos/persistence_emond_rules_file_creation.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/macos/persistence_emond_rules_process_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * relint * 2021 * Update persistence_emond_rules_process_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>