Rule(s) deprecation as part of Linux Detection Rule Review (#2163)
(cherry picked from commit e9267e544c)
This commit is contained in:
committed by
github-actions[bot]
parent
883607488a
commit
8d4606d0dc
+3
-2
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/04/24"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
+7
-3
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/02/18"
|
||||
maturity = "production"
|
||||
updated_date = "2022/07/18"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
@@ -36,9 +37,12 @@ event.category:process and event.type:(start or process_started) and process.wor
|
||||
/var/lib/command-not-found/)
|
||||
'''
|
||||
|
||||
|
||||
[[rule.threat]]
|
||||
framework = "MITRE ATT&CK"
|
||||
|
||||
[rule.threat.tactic]
|
||||
id = "TA0002"
|
||||
name = "Execution"
|
||||
reference = "https://attack.mitre.org/tactics/TA0002/"
|
||||
reference = "https://attack.mitre.org/tactics/TA0002/"
|
||||
|
||||
+3
-2
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/07/08"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
+3
-2
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/07/08"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
+3
-2
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/07/08"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
+3
-2
@@ -1,7 +1,8 @@
|
||||
[metadata]
|
||||
creation_date = "2020/07/08"
|
||||
maturity = "production"
|
||||
updated_date = "2021/03/03"
|
||||
deprecation_date = "2022/07/25"
|
||||
maturity = "deprecated"
|
||||
updated_date = "2022/07/25"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
Reference in New Issue
Block a user