-
-
Notifications
You must be signed in to change notification settings - Fork 2.3k
Proc creation lnx webshell detection #5128
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Proc creation lnx webshell detection #5128
Conversation
selection_4: | ||
Image|endswith: '/netstat' | ||
CommandLine|contains: 'localgroup' |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please provide logs related to the netstat selection with screenshots of expected output.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@CheraghiMilad ping
@CheraghiMilad you have to fill the template or this PR will get closed. As it is stated the changelog and information is mandatory |
Hey @nasbench |
Summary of the Pull Request
Some images added.
Changelog
Example Log Event
groups log
netstat log
getent log
id -Gn log
Fixed Issues
SigmaHQ Rule Creation Conventions