You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Thanks for bringing this up! I tuned the rule according to your suggestion and added a couple more tools. Once the PR is merged, this issue will be closed.
Link to Rule
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/linux/execution_potential_linux_hack_tool_launched.toml
Rule Tuning Type
False Negatives - Enhancing detection of true threats that were previously missed.
Description
This rule would benefit from being case insensitive. Then it could catch a command such as:
./LinEnum.sh
Currently that is not detected unless the rule is modified to be case-insensitive.
Example Data
The text was updated successfully, but these errors were encountered: