diff --git a/rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml b/rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml index e0896e5cc..4cf8e6fd7 100644 --- a/rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml +++ b/rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml @@ -2,9 +2,9 @@ creation_date = "2023/10/26" integration = ["cloud_defend"] maturity = "production" -min_stack_comments = "New Integration: Cloud Defend" -min_stack_version = "8.8.0" -updated_date = "2023/12/18" +min_stack_comments = "New field added to ecs : container.security_context.privileged" +min_stack_version = "8.10.0" +updated_date = "2024/01/05" [rule] author = ["Elastic"] diff --git a/rules/integrations/cloud_defend/privilege_escalation_mount_launched_inside_a_privileged_container.toml b/rules/integrations/cloud_defend/privilege_escalation_mount_launched_inside_a_privileged_container.toml index 114ec85de..b31bbb7fb 100644 --- a/rules/integrations/cloud_defend/privilege_escalation_mount_launched_inside_a_privileged_container.toml +++ b/rules/integrations/cloud_defend/privilege_escalation_mount_launched_inside_a_privileged_container.toml @@ -2,9 +2,9 @@ creation_date = "2023/10/26" integration = ["cloud_defend"] maturity = "production" -min_stack_comments = "New Integration: Cloud Defend" -min_stack_version = "8.8.0" -updated_date = "2023/12/18" +min_stack_comments = "New field added to ecs : container.security_context.privileged" +min_stack_version = "8.10.0" +updated_date = "2024/01/05" [rule] author = ["Elastic"]