Link to Rule
https://github.com/elastic/detection-rules/blob/main/rules/linux/persistence_systemd_netcon.toml
Rule Tuning Type
False Positives - Reducing benign events mistakenly identified as threats.
Description
Rule "Suspicious Network Connection via systemd" alerts about /opt/unified-monitoring-agent/embedded/bin/ruby.
This is an Oracle OCI component.
Potentially useful fields:
process.executable /opt/unified-monitoring-agent/embedded/bin/ruby
Example Data
No response