Closed 72nomada closed 1 year ago
Tester | PR commit |
---|---|
@juliamagan | https://github.com/wazuh/wazuh/pull/13673/commits/b0a1c2f4cf3e225916b1c534c47fdb98cb0fbf04 |
OS | OS version | Deployment | Image/AMI | Notes |
---|---|---|---|---|
CentOS | CentOS 8 | Vagrant | qactl/centos_8 |
wazuh-manager |
---|
4.4.0 |
runtests.py
:green_circle:Setting other executables should be covered by 89501. 89502 only exists to rise the alert level when extra scary command interpreters are registered. Probably the description could be improved and and it looks like the if_group tag is superfluous
Everything has been fixed
🟢 | Solved |
The development is approved taking into account the following considerations:
(1) Improve destination field from rule 89502. 🟢
Adding rules for Sysmon ID 20 events