LoFP LoFP / legitimate overwrite of files.

Techniques

Sample rules

Overwriting the File with Dev Zero or Null

Description

Detects overwriting (effectively wiping/deleting) of a file.

Detection logic

condition: selection
selection:
  a0|contains: dd
  a1|contains:
  - if=/dev/null
  - if=/dev/zero
  type: EXECVE