Skip to content

Commit

Permalink
Update rules/linux/execution_executable_stack_execution.toml
Browse files Browse the repository at this point in the history
Co-authored-by: Terrance DeJesus <[email protected]>
  • Loading branch information
Aegrah and terrancedejesus authored Jan 17, 2025
1 parent 80715ec commit 99fd11a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion rules/linux/execution_executable_stack_execution.toml
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ tags = [
timestamp_override = "event.ingested"
type = "query"
query = '''
host.os.type:linux and event.dataset:"system.syslog" and process.name:kernel and
host.os.type:"linux" and event.dataset:"system.syslog" and process.name:"kernel" and
message:"started with executable stack"
'''

Expand Down

0 comments on commit 99fd11a

Please sign in to comment.