mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Update 900000-exclusion_rules.xml
This commit is contained in:
committed by
GitHub
parent
5fd6768d7a
commit
dbe19557bd
@@ -835,10 +835,17 @@
|
|||||||
<id>T1059.005</id>
|
<id>T1059.005</id>
|
||||||
</mitre>
|
</mitre>
|
||||||
</rule>
|
</rule>
|
||||||
<!-- Exclude Ossec Process For Tetragon -->
|
<!-- Exclude Graylog Java Process for Tetragon -->
|
||||||
<rule id="900117" level="1">
|
<rule id="900117" level="1">
|
||||||
|
<if_sid>700002</if_sid>
|
||||||
|
<field name="process.kprobe.process.binary" type="pcre2">^\/usr\/share\/graylog-server\/jvm\/bin\/java$</field>
|
||||||
|
<description>Exclude ossec</description>
|
||||||
|
<options>no_full_log</options>
|
||||||
|
</rule>
|
||||||
|
<!-- Exclude Ossec Process -->
|
||||||
|
<rule id="900118" level="1">
|
||||||
<if_group>tetragon</if_group>
|
<if_group>tetragon</if_group>
|
||||||
<field name="process.exec.process.cwd">^/var/ossec$</field>
|
<field name="process.exec.process.cwd" type="pcre2">^\/var\/ossec$</field>
|
||||||
<description>Exclude ossec</description>
|
<description>Exclude ossec</description>
|
||||||
<options>no_full_log</options>
|
<options>no_full_log</options>
|
||||||
</rule>
|
</rule>
|
||||||
|
Reference in New Issue
Block a user