splunk/security_content

[BUG] System Processes Run From Unexpected Locations - missing field for Risk Message

ccl0utier opened this issue · 2 comments

Description

The rule System Processes Run From Unexpected Locations uses the process_path field in its Risk Message, but the field is not part of the tstats command output fields.

We might want to add it.

Version

Latest version of ESCU

Thank you @ccl0utier - I have a branch with this change here:
#2872

I believe this was fixed and shipped thank you again for raising @ccl0utier.