mirror of
				https://github.com/socfortress/Wazuh-Rules.git
				synced 2025-10-31 03:43:32 +00:00 
			
		
		
		
	Update 200200-osquery.xml
This commit is contained in:
		
				
					committed by
					
						 GitHub
						GitHub
					
				
			
			
				
	
			
			
			
						parent
						
							69582a0eb8
						
					
				
				
					commit
					36303c9f58
				
			| @@ -417,7 +417,7 @@ | |||||||
|   <group>bpf_process_events,</group> |   <group>bpf_process_events,</group> | ||||||
|   </rule> |   </rule> | ||||||
|    |    | ||||||
|   <rule id="200272" level="12"> |   <rule id="200272" level="10"> | ||||||
|   <if_sid>200223</if_sid> |   <if_sid>200223</if_sid> | ||||||
|   <field name="columns.cmdline">chage|passwd</field> |   <field name="columns.cmdline">chage|passwd</field> | ||||||
|   <field name="columns.cmdline">--list|-l|-S|--status</field> |   <field name="columns.cmdline">--list|-l|-S|--status</field> | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user