elastic-protections
high
eql
Egress Connection by a YUM Package Manager Descendant
Detects suspicious network events executed by the Yum package manager, potentially indicating persistence through a Yum backdoor. In Linux, Yum (Yellowdog Updater, Modified) is a command-line utility used for handling packages on Fedora-based systems, providing functions for installing, updating, upgrading, and removing software along with managing package repositories. Attackers can backdoor Yum to gain persistence by injecting malicious code into plugins that Yum runs, thereby ensuring continu