mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
Update lnx_shell_priv_esc_prep.yml
This commit is contained in:
parent
23021aa110
commit
ccdda5e82b
@ -62,7 +62,7 @@ detection:
|
|||||||
- 'find / -perm -u=s'
|
- 'find / -perm -u=s'
|
||||||
- 'find / -perm -g=s'
|
- 'find / -perm -g=s'
|
||||||
- 'find / -perm -4000'
|
- 'find / -perm -4000'
|
||||||
- 'find / -perm -2000
|
- 'find / -perm -2000'
|
||||||
timeframe: 30m
|
timeframe: 30m
|
||||||
condition: keywords | count() by host > 6
|
condition: keywords | count() by host > 6
|
||||||
falsepositives:
|
falsepositives:
|
||||||
|
Loading…
Reference in New Issue
Block a user