SigmaHQ / sigma

Main Sigma Rule Repository
Other
7.84k stars 2.12k forks source link

Update proc_creation_lnx_exploit_cve_2024_3094_sshd_child_process.yml #4811

Closed ruppde closed 2 months ago

ruppde commented 2 months ago

Fix FP reported by @Neo23x0

Also require "root" to be in the command line as shown in POC repo: image

See https://github.com/amlweems/xzbot?tab=readme-ov-file#backdoor-demo

image

SigmaHQ Rule Creation Conventions

Neo23x0 commented 2 months ago

I added the "modified" field and set the date to 2024/04/12. I'm pulling this request because we see a set of FPs in THOR Cloud with THOR 10.7 applying the Sigma rules on process trees on Linux systems.