CrowdStrike / detection-container

https://quay.io/repository/crowdstrike/detection-container
The Unlicense
39 stars 20 forks source link

No detections is found #29

Closed serai-nick-chan closed 2 years ago

serai-nick-chan commented 2 years ago

I tried a few actions like these:

~ # sh -c "/bin/grep 'x:0:' /etc/passwd > /tmp/passwords"
~ # 
~ # 
~ # sh -c whoami '[S];pwd;echo [E]'
root
$ cp /usr/bin/whoami ./whoami.rtf; ./whoami.rtf
app

When I go to Investigate > Detections There's still no detections found.

isimluk commented 2 years ago

Would you mind opening a support case with CrowdStrike or speaking with your account representative, please?

I am afraid github issues on this project are not well suited for support question for the sensor. Thank You.

serai-nick-chan commented 2 years ago

Ok. I will contact the support again. I was asked to post the issues here from the support ticket before.