diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 37a7f020..1c9e6b0a 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -2416,6 +2416,7 @@ tag: [process, mitre_defense_evation] # This rule is deprecated and will/should never be triggered. Keep it here for backport compatibility. +# Rule Delete or rename shell history is the preferred rule to use now. - rule: Delete Bash History desc: Detect bash history deletion condition: >