mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Update 200200-osquery.xml
This commit is contained in:
committed by
GitHub
parent
b4e473510e
commit
4cdc9485bd
@@ -617,7 +617,7 @@
|
|||||||
<!-- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_user_discovery.yml -->
|
<!-- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/auditd/lnx_auditd_user_discovery.yml -->
|
||||||
<rule id="200287" level="12">
|
<rule id="200287" level="12">
|
||||||
<if_sid>200223</if_sid>
|
<if_sid>200223</if_sid>
|
||||||
<field name="columns.cmdline">users|w|who</field>
|
<field name="columns.cmdline">^users$|^w$|^who$</field>
|
||||||
<description>Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.</description>
|
<description>Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.</description>
|
||||||
<options>no_full_log</options>
|
<options>no_full_log</options>
|
||||||
<mitre>
|
<mitre>
|
||||||
|
Reference in New Issue
Block a user