SigmaHQ/rules/linux/auditd
2020-06-16 14:46:08 -06:00
..
lnx_auditd_alter_bash_profile.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
lnx_auditd_auditing_config_change.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
lnx_auditd_create_account.yml lowercased tag 2020-05-18 10:11:32 +02:00
lnx_auditd_ld_so_preload_mod.yml OSCD QA wave 3 2020-02-02 12:41:12 +01:00
lnx_auditd_logging_config_change.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
lnx_auditd_masquerading_crond.yml fix: fixed casing and long rule titles 2020-01-30 17:26:09 +01:00
lnx_auditd_susp_C2_commands.yml Update lnx_auditd_susp_C2_commands.yml 2020-05-23 16:49:03 +02:00
lnx_auditd_susp_cmds.yml fix: fixed casing and long rule titles 2020-01-30 17:26:09 +01:00
lnx_auditd_susp_exe_folders.yml Added UUIDs to rules 2019-11-12 23:12:27 +01:00
lnx_auditd_user_discovery.yml Added UUIDs to rules 2019-11-12 23:12:27 +01:00
lnx_auditd_web_rce.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
lnx_data_compressed.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
lnx_network_sniffing.yml Added UUIDs to rules 2019-11-12 23:12:27 +01:00