/
Linux detections

Linux detections

Detects the deletion of Web Server access logs.

Source table → box.unix

Detects the deletion of sensitive Linux system logs

Source table → box.unix

Detects modification to the sudoers file. The sudoers file determines which users have the ability to run with superuser permission.

Source table → box.unix

Detects potential Linux binary SSH abuse to break out from restricted environments by spawning an interactive system shell.

Source table → box.unix

Detects the maximum number of failed login attempts for a user on a Linux host.

Source table → box.unix