Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Rule Tuning] Potential Linux Hack Tool Launched #4190

Open
stuartMoorhouse opened this issue Oct 22, 2024 · 1 comment · May be fixed by #4191
Open

[Rule Tuning] Potential Linux Hack Tool Launched #4190

stuartMoorhouse opened this issue Oct 22, 2024 · 1 comment · May be fixed by #4191
Assignees
Labels
Rule: Tuning tweaking or tuning an existing rule Team: TRADE

Comments

@stuartMoorhouse
Copy link

Link to Rule

https:/elastic/protections-artifacts/blob/main/behavior/rules/linux/execution_potential_linux_hack_tool_launched.toml

Rule Tuning Type

False Negatives - Enhancing detection of true threats that were previously missed.

Description

This rule would benefit from being case insensitive. Then it could catch a command such as:

./LinEnum.sh

Currently that is not detected unless the rule is modified to be case-insensitive.

Example Data

Image

@stuartMoorhouse stuartMoorhouse added Rule: Tuning tweaking or tuning an existing rule Team: TRADE labels Oct 22, 2024
@Aegrah Aegrah linked a pull request Oct 22, 2024 that will close this issue
@Aegrah
Copy link
Contributor

Aegrah commented Oct 22, 2024

Thanks for bringing this up! I tuned the rule according to your suggestion and added a couple more tools. Once the PR is merged, this issue will be closed.

#4191

@Aegrah Aegrah self-assigned this Oct 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Rule: Tuning tweaking or tuning an existing rule Team: TRADE
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants