olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.12k stars 177 forks source link

process_parent_commandline whitelisting #41

Open whipped5000 opened 4 years ago

whipped5000 commented 4 years ago

Just wondering if it is worth adding the process_parent_commandline field as an option when whitelisting via the Process Create Whitelist

billmurrin commented 4 years ago

I would also like to see the addition of this field to the whitelist. There are a few times where this would have been good to have in the whitelist.

olafhartong commented 4 years ago

that does make sense on occasion, I'll add it