mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
410d4e5929
* [Rule Tuning] Suspicious JAR Child Process Expand rule coverage by removing the process.args containing a jar file requirement which may help detect also exploitation attempt via command injection vulnerabilities on server apps running JAVA. * Update rules/cross-platform/execution_suspicious_jar_child_process.toml