was built in the system · program = \.+


Description

$(program) $(version) was built in the system

Query · wazuh

field program="\.+"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. 70000 FreePBX parent anchor level 0
    decoded_as=FreePBX
  2. 70007 was built in the system · program = \.+ refinement level 3 this rule
    field program="\.+"

Rule dependencies

Depends on

Raw source was built in the system · program = \.+ · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="70007" level="3">
   <if_sid>70000</if_sid>
   <field name="program">\.+</field>
   <description>$(program) $(version) was built in the system</description>
 </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.