Skip to content

Uncommon shell activity - command monitoring #32

@Pilladian

Description

@Pilladian

When endpoint is monitored, it would be interesting to raise an alert whenever uncommon shell activity takes place.
Lets assume the user commonly executes a specific set of commands throughout the day. If new commands are getting executed an alert could be raised.

Metadata

Metadata

Assignees

Labels

siem ideaIdea for a siem runbook

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions