elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 491 forks source link

[Rule Tuning] Tampering of Shell Command-Line History #3648

Open psanz-estc opened 4 months ago

psanz-estc commented 4 months ago

Link to rule

https://www.elastic.co/guide/en/security/current/tampering-of-shell-command-line-history.html

Description

We should update the docs for the rules that reference the word command line or shell in it, to specify they do not log activity directly, and only external script executions or direct calls from binaries

psanz-estc commented 4 months ago

CC: @Aegrah