rule(list network_tool_binaries): add network tool names

Signed-off-by: Hiroki Suezawa <suezawa@gmail.com>
This commit is contained in:
Hiroki Suezawa 2019-12-13 22:28:21 +09:00 committed by Lorenzo Fontana
parent 28fa4a72e8
commit 23a7203e50

View File

@ -2281,7 +2281,7 @@
tags: [network, k8s, container, mitre_port_knocking]
- list: network_tool_binaries
items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep]
items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep, telnet, ssh, mitmproxy, socat]
- macro: network_tool_procs
condition: (proc.name in (network_tool_binaries))