mirror of
https://github.com/chainguard-dev/osquery-defense-kit
synced 2025-01-18 19:40:52 +00:00
Add chattr, setenforce to unexpected-sysutils
This commit is contained in:
parent
cf858d193d
commit
5eefbd0dba
@ -67,7 +67,13 @@ WHERE
|
||||
AND pe.path IN (
|
||||
'/usr/bin/sysctl',
|
||||
'/sbin/sysctl',
|
||||
'/usr/sbin/sysctl'
|
||||
'/usr/sbin/sysctl',
|
||||
'/usr/bin/chattr',
|
||||
'/sbin/chattr',
|
||||
'/usr/sbin/chattr',
|
||||
'/usr/bin/setenforce',
|
||||
'/sbin/setenforce',
|
||||
'/usr/sbin/setenforce'
|
||||
)
|
||||
AND p.parent > 0
|
||||
GROUP BY
|
||||
|
Loading…
Reference in New Issue
Block a user