From e2b0e4c32bfcc62c91f0491c3ca1b9fa244cc25c Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Tue, 15 Feb 2022 10:21:43 -0800 Subject: [PATCH] mionr --- detections/endpoint/suspcious_linux_discovery_commands.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/suspcious_linux_discovery_commands.yml b/detections/endpoint/suspcious_linux_discovery_commands.yml index e05e41eee2..ac97bf33cc 100644 --- a/detections/endpoint/suspcious_linux_discovery_commands.yml +++ b/detections/endpoint/suspcious_linux_discovery_commands.yml @@ -19,6 +19,7 @@ known_false_positives: Unless an administrator is using these commands to troubl or audit a system, the execution of these commands should be monitored. references: - https://attack.mitre.org/matrices/enterprise/linux/ +- https://attack.mitre.org/techniques/T1059/004/ - https://github.com/IvanGlinkin/AutoSUID - https://github.com/carlospolop/PEASS-ng/tree/master/linPEAS - https://github.com/rebootuser/LinEnum