From a6da209507245992215bcaf535ead823febd75ad Mon Sep 17 00:00:00 2001 From: frack113 <62423083+frack113@users.noreply.github.com> Date: Tue, 14 Sep 2021 21:02:51 +0200 Subject: [PATCH] Update lnx_auditd_system_info_discovery2.yml --- rules/linux/auditd/lnx_auditd_system_info_discovery2.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/rules/linux/auditd/lnx_auditd_system_info_discovery2.yml b/rules/linux/auditd/lnx_auditd_system_info_discovery2.yml index 60f5afa4..dc0f65b6 100644 --- a/rules/linux/auditd/lnx_auditd_system_info_discovery2.yml +++ b/rules/linux/auditd/lnx_auditd_system_info_discovery2.yml @@ -7,7 +7,7 @@ status: stable description: Detects system information discovery commands author: Ömer Günal, oscd.community date: 2020/10/08 -modified: 2020/05/30 +modified: 2021/09/14 references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1082/T1082.md tags: @@ -32,4 +32,4 @@ detection: condition: selection falsepositives: - Legitimate administration activities -level: informational \ No newline at end of file +level: informational