Collect /var/tmp and /dev/shm? #66
Closed
halpomeranz
started this conversation in
Ideas
Replies: 1 comment
-
Great! |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Right now the tool collects files in /tmp. I would suggest adding /var/tmp and /dev/shm as targets. I've seen attackers stage files in both directories.
Beta Was this translation helpful? Give feedback.
All reactions