mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
3fc4aaec0f
* [New Rule] Modification of SSH Binaries * Update persistence_credential_access_modify_ssh_binaries.toml * exclude unrelated auditbeat FP events * updated TIDs and Tactics * fix order of TIDs and Tactics * relinted * added libkeyutils.so used by Ebury Backdoor loaded by all OpenSSH processes * renamed * conv to kql and added one FP * Update rules/linux/persistence_credential_access_modify_ssh_binaries.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/linux/persistence_credential_access_modify_ssh_binaries.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>