mirror of
https://github.com/keyboardcrunch/sentinelone-queries
synced 2026-06-09 09:27:16 +00:00
fixed false pos
This commit is contained in:
@@ -9,6 +9,7 @@ mitre:
|
|||||||
subtechnique:
|
subtechnique:
|
||||||
operating_system: linux
|
operating_system: linux
|
||||||
query: SrcProcCmdLine In Contains Anycase ("useradd")
|
query: SrcProcCmdLine In Contains Anycase ("useradd")
|
||||||
false_positives: General account maintenance.
|
false_positives:
|
||||||
|
- General account maintenance.
|
||||||
tags:
|
tags:
|
||||||
references:
|
references:
|
||||||
|
|||||||
Reference in New Issue
Block a user