Files
artex/detections/tests/sigma_match/events/destructive_command_hunting.json
dela 0335d572de
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
detections / detections (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
First Commit
2026-10-09 08:38:16 +08:00

14 lines
968 B
JSON

{
"note": "process_creation telemetry (CommandLine). The rule hunts destructive shell/DB/availability commands via '1 of selection_*', so one representative command from each of the three selection groups must match. Benign commands — including a plain 'rm' without the recursive/force flags — must not. (The rule's own false-positive note documents that lowercase coreutils 'truncate' DOES share the TRUNCATE token and must be allow-listed, so it is intentionally not used here as a negative.)",
"positive": [
{"CommandLine": "rm -rf /var/www/html", "Image": "/usr/bin/rm"},
{"CommandLine": "mysql -u root -e 'DROP TABLE customers'", "Image": "/usr/bin/mysql"},
{"CommandLine": "iptables -F", "Image": "/usr/sbin/iptables"}
],
"negative": [
{"CommandLine": "ls -la /var/www/html", "Image": "/usr/bin/ls"},
{"CommandLine": "rm /tmp/scratch.txt", "Image": "/usr/bin/rm"},
{"CommandLine": "git status", "Image": "/usr/bin/git"}
]
}