mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-30 03:13:35 +00:00
Update 200200-osquery.xml
This commit is contained in:
committed by
GitHub
parent
69582a0eb8
commit
36303c9f58
@@ -417,7 +417,7 @@
|
|||||||
<group>bpf_process_events,</group>
|
<group>bpf_process_events,</group>
|
||||||
</rule>
|
</rule>
|
||||||
|
|
||||||
<rule id="200272" level="12">
|
<rule id="200272" level="10">
|
||||||
<if_sid>200223</if_sid>
|
<if_sid>200223</if_sid>
|
||||||
<field name="columns.cmdline">chage|passwd</field>
|
<field name="columns.cmdline">chage|passwd</field>
|
||||||
<field name="columns.cmdline">--list|-l|-S|--status</field>
|
<field name="columns.cmdline">--list|-l|-S|--status</field>
|
||||||
|
|||||||
Reference in New Issue
Block a user