updating search syntax, splitting process name and cmdline and adding category

This commit is contained in:
remotephone@gmail.com 2020-10-12 22:49:19 -05:00
parent 476a3c04d9
commit 89c8a589a5

View File

@ -8,12 +8,14 @@ references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.002/T1070.002.md
logsource:
product: macos
category: process_creation
detection:
selection:
- ProcessName: 'rm'
CommandLine|contains:
- 'rm -rf /var/log'
- 'rm -rf /private/var/log'
- 'rm -rf /Users/*/Library/Logs/'
- '-rf /var/log'
- '-rf /private/var/log'
- '-rf /Users/*/Library/Logs/'
condition: selection
falsepositives:
- Legitimate administration activities