elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Tuning] Executable Bit Set for Potential Persistence Script #3929

Closed Aegrah closed 2 months ago

Aegrah commented 2 months ago

Summary

RHEL derivatives require execution permissions to be set for /etc/rc.d/rc.local when attempting to manually enable and execute /etc/rc.local. Added this to the rule, to ensure coverage.

protectionsmachine commented 2 months ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation