elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 492 forks source link

[Rule Tuning] Executable Bit Set for Potential Persistence Script #3812

Closed Aegrah closed 3 months ago

Aegrah commented 3 months ago

Summary

Increased rule scope for this rule to not just cover /etc/rc.local and /etc/rc.common, but more scripts that can potentially be used for persistence. 0 hits in telemetry last 90d, 66 hits in my stack (related to malware, RTA's and testing).

image