Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Rule Tuning] Tampering of Shell Command-Line History #3648

Open
psanz-estc opened this issue May 6, 2024 · 1 comment
Open

[Rule Tuning] Tampering of Shell Command-Line History #3648

psanz-estc opened this issue May 6, 2024 · 1 comment
Assignees
Labels
Rule: Tuning tweaking or tuning an existing rule

Comments

@psanz-estc
Copy link

Link to rule

https://www.elastic.co/guide/en/security/current/tampering-of-shell-command-line-history.html

Description

We should update the docs for the rules that reference the word command line or shell in it, to specify they do not log activity directly, and only external script executions or direct calls from binaries

@psanz-estc psanz-estc added the Rule: Tuning tweaking or tuning an existing rule label May 6, 2024
@psanz-estc
Copy link
Author

CC: @Aegrah

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: Tuning tweaking or tuning an existing rule
Projects
None yet
Development

No branches or pull requests

2 participants