Skip to content

[Rule Tuning] Fixing Typo in the macOS persistence emond modification rule - #6529

Open
litemars wants to merge 4 commits into
elastic:mainfrom
litemars:peristence_emond_typo
Open

[Rule Tuning] Fixing Typo in the macOS persistence emond modification rule#6529
litemars wants to merge 4 commits into
elastic:mainfrom
litemars:peristence_emond_typo

Conversation

@litemars

Copy link
Copy Markdown
Contributor

Pull Request

Summary - What I changed

The file path was wrong, please check this link as reference: https://cocomelonc.github.io/macos/2026/04/02/mac-malware-persistence-9.html

@w0rk3r w0rk3r left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice, thanks @litemars

Can you bump the updated_date?

@litemars

Copy link
Copy Markdown
Contributor Author

Hi @w0rk3r,

Could I also write my name in the author section even though I didn't fully create the rule? I feel like I have already fine-tuned more than 15 rules in Elastic.

Cheers,
M

@eric-forte-elastic

eric-forte-elastic commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Hi @w0rk3r,

Could I also write my name in the author section even though I didn't fully create the rule? I feel like I have already fine-tuned more than 15 rules in Elastic.

Cheers, M

Given that this change is a substantial part of the rule, yes I think you should add your name. We have many rules that are co-authored (including co-authored as a result of tuning).

Precedence:

@eric-forte-elastic eric-forte-elastic left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tuning looks good 👍

@w0rk3r

w0rk3r commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

@litemars, I don't see a problem. Go ahead, I'll wait for it and then we can merge :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants