Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Uncommon shell activity - command monitoring #32

Open
Pilladian opened this issue Aug 27, 2022 · 0 comments
Open

Uncommon shell activity - command monitoring #32

Pilladian opened this issue Aug 27, 2022 · 0 comments
Assignees
Labels
siem idea Idea for a siem runbook

Comments

@Pilladian
Copy link
Owner

When endpoint is monitored, it would be interesting to raise an alert whenever uncommon shell activity takes place.
Lets assume the user commonly executes a specific set of commands throughout the day. If new commands are getting executed an alert could be raised.

@Pilladian Pilladian added the siem idea Idea for a siem runbook label Aug 27, 2022
@Pilladian Pilladian self-assigned this Aug 27, 2022
@Pilladian Pilladian changed the title Umcommon shell activity - command monitoring Uncommon shell activity - command monitoring Aug 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
siem idea Idea for a siem runbook
Projects
None yet
Development

No branches or pull requests

1 participant