Fix references to p0.cmdline

This commit is contained in:
Thomas Stromberg 2023-03-17 15:38:22 -04:00
parent e1db6fc2de
commit 15c666a170
Failed to extract signature
2 changed files with 4 additions and 4 deletions

View File

@ -103,7 +103,7 @@ WHERE
OR p0_name LIKE '%attack%' -- Unusual behaviors
OR p0_cmd LIKE '%powershell%'
OR p0_cmd LIKE '%chattr -i%'
OR p0.cmdline LIKE '%dd if=/dev/%'
OR p0_cmd LIKE '%dd if=/dev/%'
OR p0_cmd LIKE '%cat /dev/null >%'
OR p0_cmd LIKE '%truncate -s0 %'
OR p0_cmd LIKE '%touch%acmr%'

View File

@ -94,12 +94,12 @@ WHERE
OR p.cmdline LIKE '%dd if=/dev/%'
)
AND NOT (
p0.cmdline LIKE '%UserKnownHostsFile=/dev/null%'
p0_cmd LIKE '%UserKnownHostsFile=/dev/null%'
AND p1.name == 'limactl'
)
AND NOT (
p0.cmdline LIKE '%sh -i'
AND p1.cmdline LIKE '%pipenv shell'
p0_cmd LIKE '%sh -i'
AND p1_cmd LIKE '%pipenv shell'
)
AND NOT p0_cmd IN ('pkill -f Jabra Direct')
GROUP BY