mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
5a48934822
I suggest a new point of view to detect that bash_history has been cleared : Instead of trying to detect all the commands that can do that, we could monitor the size of the file and log whenever it has less than 1 line. |
||
---|---|---|
.. | ||
application | ||
apt | ||
cloud | ||
compliance | ||
generic | ||
linux | ||
network | ||
proxy | ||
web | ||
windows |