22creation_date = " 2024/06/03"
33integration = [" fim" ]
44maturity = " production"
5- updated_date = " 2025/01/22 "
5+ updated_date = " 2025/12/04 "
66
77[rule ]
88author = [" Elastic" ]
@@ -21,6 +21,10 @@ name = "Potential Persistence via File Modification"
2121references = [
2222 " https://www.elastic.co/security-labs/primer-on-persistence-mechanisms" ,
2323 " https://www.elastic.co/security-labs/sequel-on-persistence-mechanisms" ,
24+ " https://www.elastic.co/security-labs/continuation-on-persistence-mechanisms" ,
25+ " https://www.elastic.co/security-labs/approaching-the-summit-on-persistence" ,
26+ " https://www.elastic.co/security-labs/the-grand-finale-on-linux-persistence" ,
27+ " https://slayer0x.github.io/awscli/" ,
2428]
2529risk_score = 21
2630rule_id = " 192657ba-ab0e-4901-89a2-911d611eee98"
@@ -94,6 +98,10 @@ file.path : (
9498 "/home/*/.config/fish/config.fish", "/root/.config/fish/config.fish",
9599 "/home/*/.kshrc", "/root/.kshrc",
96100
101+ // Alias files
102+ "/home/*/.bash_aliases", "/root/.bash_aliases", "/home/*/.zsh_aliases", "/root/.zsh_aliases",
103+ "/home/*/.aws/cli/alias", "/root/.aws/cli/alias",
104+
97105 // runtime control
98106 "/etc/rc.common", "/etc/rc.local",
99107
0 commit comments