Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update proc_creation_lnx_exploit_cve_2024_3094_sshd_child_process.yml #4811

Merged
merged 2 commits into from
Apr 14, 2024
Merged

Update proc_creation_lnx_exploit_cve_2024_3094_sshd_child_process.yml #4811

merged 2 commits into from
Apr 14, 2024

Conversation

ruppde
Copy link
Contributor

@ruppde ruppde commented Apr 12, 2024

Fix FP reported by @Neo23x0

Also require "root" to be in the command line as shown in POC repo:
image

See https://github.com/amlweems/xzbot?tab=readme-ov-file#backdoor-demo

image

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@Neo23x0
Copy link
Collaborator

Neo23x0 commented Apr 14, 2024

I added the "modified" field and set the date to 2024/04/12.
I'm pulling this request because we see a set of FPs in THOR Cloud with THOR 10.7 applying the Sigma rules on process trees on Linux systems.

@Neo23x0 Neo23x0 merged commit 626a6fc into SigmaHQ:master Apr 14, 2024
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants