rule(list network_tool_binaries): delete ssh from the list

Signed-off-by: Hiroki Suezawa <suezawa@gmail.com>
This commit is contained in:
Hiroki Suezawa 2019-12-17 00:44:59 +09:00 committed by Lorenzo Fontana
parent 23a7203e50
commit cd94d05cd9

View File

@ -2281,7 +2281,7 @@
tags: [network, k8s, container, mitre_port_knocking] tags: [network, k8s, container, mitre_port_knocking]
- list: network_tool_binaries - list: network_tool_binaries
items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep, telnet, ssh, mitmproxy, socat] items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep, telnet, mitmproxy, socat]
- macro: network_tool_procs - macro: network_tool_procs
condition: (proc.name in (network_tool_binaries)) condition: (proc.name in (network_tool_binaries))