Skip to content

Commit 95bec07

Browse files
authored
Update initial_access_execution_susp_react_serv_child.toml
1 parent cabf1c2 commit 95bec07

File tree

1 file changed

+3
-4
lines changed

1 file changed

+3
-4
lines changed

rules/cross-platform/initial_access_execution_susp_react_serv_child.toml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
creation_date = "2025/12/04"
33
integration = ["endpoint", "windows", "auditd_manager", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2025/12/08"
5+
updated_date = "2025/12/10"
66

77
[rule]
88
author = ["Elastic"]
@@ -101,12 +101,11 @@ process where event.type == "start" and event.action in ("exec", "executed", "st
101101
)
102102
and (
103103
?process.working_directory : (
104-
"*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*bin/next*", "*--experimental-https*", "*app/server*",
105-
"*.pnpm/next*", "*/app/*", "*next/dist/server*", "*react-scripts*") or
104+
"*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*bin/next*", "*.pnpm/next*", "*next/dist/server*", "*react-scripts*") or
106105
(
107106
process.parent.name in ("node", "bun", "node.exe", "bun.exe") and
108107
process.parent.command_line : (
109-
"*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*next-server*", "*server.js*", "*bin/next*",
108+
"*react-dom*", "*/.next*", "*node_modules/next*", "*react-server*", "*next-server*", "* server.js*", "*start-server.js*", "*bin/next*",
110109
"*--experimental-https*", "*app/server*", "*.pnpm/next*", "*next start*", "*next dev*", "*react-scripts start*", "*next/dist/server*"
111110
)
112111
)

0 commit comments

Comments
 (0)