jamf / jamfprotect

A repository for open-source resources created for use with or alongside Jamf Protect.
MIT License
188 stars 26 forks source link

generic / scp_file_copied_remote_destination #121

Closed txhaflaire closed 6 months ago

txhaflaire commented 7 months ago

Custom Analytics to detect the use of scp specifically to transfer files to a remote destination or a generic rule to detect either scp, sftp or rsync. provided Context Items could highlight source file and destination paths.

image