Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

show alert levels and rule names for stacking commands #112

Closed
YamatoSecurity opened this issue Feb 16, 2024 · 0 comments · Fixed by #113
Closed

show alert levels and rule names for stacking commands #112

YamatoSecurity opened this issue Feb 16, 2024 · 0 comments · Fixed by #113
Assignees
Labels
enhancement New feature or request
Milestone

Comments

@YamatoSecurity
Copy link
Collaborator

For the following commands:

stack-cmdlines
stack-processes
stack-services
stack-tasks

when outputting to the terminal, it would be nice to display in a table similar to the extract-scriptblocks command and add two columns: Level and Alerts
Screenshot 2024-02-16 at 15 14 59

Any time a command line, process, service, task, etc.. has a low or higher alert, we output that information in the same color scheme as extract-scriptblocks. This will make it easier to identify malicious command lines, processes, etc...

@fukusuket Could I ask you to do this one as you are the most familiar with it?

@YamatoSecurity YamatoSecurity added the enhancement New feature or request label Feb 16, 2024
@fukusuket fukusuket self-assigned this Feb 16, 2024
@fukusuket fukusuket added this to the v2.4.0 milestone Feb 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants