LoFP LoFP / legitimate reconfiguration of service.

Techniques

Sample rules

Systemd Service Reload or Start

Description

Detects a reload or a start of a service.

Detection logic

condition: selection
selection:
  a0|contains: systemctl
  a1|contains:
  - daemon-reload
  - start
  type: EXECVE