Files
splunk-security_content/lookups/linux_tool_discovery_process.yml
2024-12-23 15:45:58 -08:00

12 lines
331 B
YAML

name: linux_tool_discovery_process
date: 2024-12-23
version: 2
id: f0d8b1c8-4ca0-4765-858a-ab0dea68c399
author: Splunk Threat Research Team
lookup_type: csv
description: A list of suspicious bash commonly used by attackers via scripts
default_match: false
match_type:
- WILDCARD(process)
min_matches: 1
case_sensitive_match: false