mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update detections/endpoint/linux_auditd_change_file_owner_to_root.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
This commit is contained in:
@@ -4,7 +4,7 @@ version: 6
|
||||
date: '2025-02-20'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
type: Anomaly
|
||||
description: The following analytic detects the use of the 'chown' command to change
|
||||
a file owner to 'root' on a Linux system. It leverages Linux Auditd telemetry, specifically
|
||||
monitoring command-line executions and process details. This activity is significant
|
||||
|
||||
Reference in New Issue
Block a user