mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Update lnx_shell_priv_esc_prep.yml
This commit is contained in:
parent
23021aa110
commit
ccdda5e82b
@ -62,7 +62,7 @@ detection:
|
||||
- 'find / -perm -u=s'
|
||||
- 'find / -perm -g=s'
|
||||
- 'find / -perm -4000'
|
||||
- 'find / -perm -2000
|
||||
- 'find / -perm -2000'
|
||||
timeframe: 30m
|
||||
condition: keywords | count() by host > 6
|
||||
falsepositives:
|
||||
|
Loading…
Reference in New Issue
Block a user