Add addl bitnami conditions.

This commit is contained in:
Mark Stemm 2017-11-07 09:52:14 -08:00
parent 480ba4e0f8
commit 15e2d0bf7e

View File

@ -464,7 +464,9 @@
proc.aname[4]=assemble)) proc.aname[4]=assemble))
- macro: node_running_bitnami - macro: node_running_bitnami
condition: proc.pname=node and proc.cmdline startswith "sh -c /opt/bitnami" condition: (proc.pname=node and
(proc.cmdline startswith "sh -c /opt/bitnami" or
proc.cmdline startswith "sh -c bin/redis-server /opt/bitnami"))
- macro: node_running_threatstack - macro: node_running_threatstack
condition: proc.pcmdline startswith "node /opt/threatstack/node_modules" condition: proc.pcmdline startswith "node /opt/threatstack/node_modules"