|
2 | 2 | creation_date = "2025/12/04" |
3 | 3 | integration = ["endpoint", "windows", "auditd_manager", "sentinel_one_cloud_funnel"] |
4 | 4 | maturity = "production" |
5 | | -updated_date = "2025/12/08" |
| 5 | +updated_date = "2025/12/10" |
6 | 6 |
|
7 | 7 | [rule] |
8 | 8 | author = ["Elastic"] |
@@ -101,12 +101,11 @@ process where event.type == "start" and event.action in ("exec", "executed", "st |
101 | 101 | ) |
102 | 102 | and ( |
103 | 103 | ?process.working_directory : ( |
104 | | - "*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*bin/next*", "*--experimental-https*", "*app/server*", |
105 | | - "*.pnpm/next*", "*/app/*", "*next/dist/server*", "*react-scripts*") or |
| 104 | + "*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*bin/next*", "*.pnpm/next*", "*next/dist/server*", "*react-scripts*") or |
106 | 105 | ( |
107 | 106 | process.parent.name in ("node", "bun", "node.exe", "bun.exe") and |
108 | 107 | process.parent.command_line : ( |
109 | | - "*react-dom*", "*.next*", "*node_modules/next*", "*react-server*", "*next-server*", "*server.js*", "*bin/next*", |
| 108 | + "*react-dom*", "*/.next*", "*node_modules/next*", "*react-server*", "*next-server*", "* server.js*", "*start-server.js*", "*bin/next*", |
110 | 109 | "*--experimental-https*", "*app/server*", "*.pnpm/next*", "*next start*", "*next dev*", "*react-scripts start*", "*next/dist/server*" |
111 | 110 | ) |
112 | 111 | ) |
|
0 commit comments