From 5b8593559cd8f19086f7b650d598b23e3d8eb6cf Mon Sep 17 00:00:00 2001 From: Isai <59296946+imays11@users.noreply.github.com> Date: Tue, 20 Sep 2022 17:09:22 -0400 Subject: [PATCH] [Rule Tuning] Kubernetes - update min_stack for new rules (#2310) ## Link to rule https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/discovery_denied_service_account_request.toml https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/initial_access_anonymous_request_authorized.toml https://github.com/elastic/detection-rules/blob/main/rules/integrations/kubernetes/privilege_escalation_suspicious_assignment_of_controller_service_account.toml ## Description min_stack change to 8.4 with new required fields added to Kubernetes Integration --- .../discovery_denied_service_account_request.toml | 6 +++--- .../initial_access_anonymous_request_authorized.toml | 6 +++--- ...suspicious_assignment_of_controller_service_account.toml | 6 +++--- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/rules/integrations/kubernetes/discovery_denied_service_account_request.toml b/rules/integrations/kubernetes/discovery_denied_service_account_request.toml index 2214c59ff..5974b4248 100644 --- a/rules/integrations/kubernetes/discovery_denied_service_account_request.toml +++ b/rules/integrations/kubernetes/discovery_denied_service_account_request.toml @@ -2,9 +2,9 @@ creation_date = "2022/09/13" integration = "kubernetes" maturity = "production" -min_stack_comments = "New fields added: required_fields, related_integrations, setup" -min_stack_version = "8.3.0" -updated_date = "2022/09/15" +min_stack_comments = "New fields added to Kubernetes Integration" +min_stack_version = "8.4.0" +updated_date = "2022/09/20" [rule] author = ["Elastic"] diff --git a/rules/integrations/kubernetes/initial_access_anonymous_request_authorized.toml b/rules/integrations/kubernetes/initial_access_anonymous_request_authorized.toml index f8f4a350d..af92e9e4d 100644 --- a/rules/integrations/kubernetes/initial_access_anonymous_request_authorized.toml +++ b/rules/integrations/kubernetes/initial_access_anonymous_request_authorized.toml @@ -2,9 +2,9 @@ creation_date = "2022/09/13" integration = "kubernetes" maturity = "production" -min_stack_comments = "New fields added: required_fields, related_integrations, setup" -min_stack_version = "8.3.0" -updated_date = "2022/09/13" +min_stack_comments = "New fields added to Kubernetes Integration" +min_stack_version = "8.4.0" +updated_date = "2022/09/20" [rule] author = ["Elastic"] diff --git a/rules/integrations/kubernetes/privilege_escalation_suspicious_assignment_of_controller_service_account.toml b/rules/integrations/kubernetes/privilege_escalation_suspicious_assignment_of_controller_service_account.toml index 4a2cfde1d..c6a1ed0de 100644 --- a/rules/integrations/kubernetes/privilege_escalation_suspicious_assignment_of_controller_service_account.toml +++ b/rules/integrations/kubernetes/privilege_escalation_suspicious_assignment_of_controller_service_account.toml @@ -2,9 +2,9 @@ creation_date = "2022/09/13" integration = "kubernetes" maturity = "production" -min_stack_comments = "New fields added: required_fields, related_integrations, setup" -min_stack_version = "8.3.0" -updated_date = "2022/09/15" +min_stack_comments = "New fields added to Kubernetes Integration" +min_stack_version = "8.4.0" +updated_date = "2022/09/20" [rule] author = ["Elastic"]