mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update linux_possible_append_command_to_profile_config_file.yml
This commit is contained in:
@@ -21,7 +21,7 @@ how_to_implement: To successfully implement this search, you need to be ingestin
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
|
||||
Sysmon TA.
|
||||
known_false_positives: Administrator or network operator can use this commandline for automation purposes. filter is needed
|
||||
known_false_positives: Administrator or network operator can use this commandline for automation purposes. Please update the filter macros to remove false positives.
|
||||
references:
|
||||
- https://unix.stackexchange.com/questions/129143/what-is-the-purpose-of-bashrc-and-how-does-it-work
|
||||
- https://attack.mitre.org/techniques/T1546/004/
|
||||
|
||||
Reference in New Issue
Block a user