mirror of
https://github.com/valitydev/atomic-threat-coverage.git
synced 2024-11-06 09:35:21 +00:00
add DN_0092_unix_generic_syslog
This commit is contained in:
parent
88f943ed5c
commit
c556bbf7ea
18
data_needed/DN_0092_unix_generic_syslog.yml
Normal file
18
data_needed/DN_0092_unix_generic_syslog.yml
Normal file
@ -0,0 +1,18 @@
|
||||
title: DN_0092_unix_generic_syslog
|
||||
description: >
|
||||
Unix generic syslog
|
||||
loggingpolicy:
|
||||
- None
|
||||
references:
|
||||
- https://github.com/Neo23x0/sigma/blob/master/rules/linux/lnx_buffer_overflows.yml
|
||||
category: OS Logs
|
||||
platform: Unix
|
||||
type: generic
|
||||
channel: syslog
|
||||
provider: syslog
|
||||
fields:
|
||||
- timestamp
|
||||
- uid
|
||||
- message
|
||||
sample: | # Solaris syslog
|
||||
Nov 12 18:47:02 foo.bar.baz unix: rpc.ttdbserverd[1932] attempt to execute code on stack by uid 0
|
Loading…
Reference in New Issue
Block a user