Files
sigma-rules/rules/macos
Samirbous cfd42babd1 [New Rule] Enumeration of Users or Groups using Built-In Commands (#848)
* [New Rule] Enumeration of Users or Groups using Built-In Commands

* Update discovery_users_domain_built_in_commands.toml

* added search option

* excluded some noisy processes

* Update discovery_users_domain_built_in_commands.toml

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* Update rules/macos/discovery_users_domain_built_in_commands.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
2021-02-09 10:50:39 +01:00
..