Skip to content

Commit

Permalink
updated
Browse files Browse the repository at this point in the history
Signed-off-by: h4l0gen <[email protected]>
  • Loading branch information
h4l0gen committed Mar 25, 2024
1 parent 08a6c8b commit efa83ca
Show file tree
Hide file tree
Showing 4 changed files with 446 additions and 445 deletions.
16 changes: 8 additions & 8 deletions rules/falco-deprecated_rules.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -111,8 +111,8 @@
terminal=%proc.tty %container.info)
priority: NOTICE
tags: [
maturity_deprecated, host, container, network,
mitre_latera_movement, T1021.004
maturity_deprecated, host, container, network,
mitre_latera_movement, T1021.004
]

# These rules and supporting macros are more of an example for how to
Expand Down Expand Up @@ -157,8 +157,8 @@
priority: NOTICE
tags: [
maturity_deprecated, host, container, network,
mitre_command_and_control, TA0011
maturity_deprecated, host, container, network,
mitre_command_and_control, TA0011
]
# Use this to test whether the event occurred within a container.
# When displaying container information in the output field, use
Expand Down Expand Up @@ -222,8 +222,8 @@
terminal=%proc.tty %container.info)
priority: WARNING
tags: [
maturity_deprecated, container, network, mitre_discovery, TA0011,
NIST_800-53_CM-7
maturity_deprecated, container, network, mitre_discovery, TA0011,
NIST_800-53_CM-7
]

- list: c2_server_ip_list
Expand Down Expand Up @@ -258,6 +258,6 @@
priority: WARNING
enabled: false
tags: [
maturity_deprecated, host, container, network,
mitre_command_and_control, TA0011
maturity_deprecated, host, container, network,
mitre_command_and_control, TA0011
]
Loading

0 comments on commit efa83ca

Please sign in to comment.