Update lnx_auditd_steghide_extract_steganography.yml

This commit is contained in:
zakibro 2021-09-11 11:19:21 +02:00 committed by GitHub
parent d0741f9f3a
commit 6412ddaaee
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -17,15 +17,12 @@ logsource:
product: linux
service: auditd
detection:
type:
Steghide:
type: EXECVE
commands:
a0: steghide
a1: extract
a2:
a2: '-sf'
a3:
a3|endswith:
- '.jpg'
- '.png'
condition: type and commands and a2 and a3
condition: Steghide