Fix Minstack version for windows integration (#4214)
This commit is contained in:
@@ -1,8 +1,10 @@
|
||||
[metadata]
|
||||
creation_date = "2020/12/21"
|
||||
integration = ["endpoint", "windows"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/05/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -1,8 +1,10 @@
|
||||
[metadata]
|
||||
creation_date = "2020/03/25"
|
||||
integration = ["endpoint", "windows"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/06/18"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2023/01/11"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/03/12"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/19"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2023/01/12"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/03/12"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/15"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/01/11"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/19"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/07/18"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/04/03"
|
||||
integration = ["endpoint", "windows", "system"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/09/23"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/12/19"
|
||||
integration = ["windows", "system"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/09/23"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/07/10"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/09"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/01/24"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/12/07"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/01/23"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/07/26"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/05"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/03/27"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/01/24"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/03/14"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/01/27"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/01/26"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/02/22"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/14"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/01/17"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/11/12"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic", "Anabella Cristaldi"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/03/19"
|
||||
integration = ["windows", "system"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/09/23"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/03/25"
|
||||
integration = ["endpoint", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/03/25"
|
||||
integration = ["endpoint", "windows", "system"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2021/10/15"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/09/30"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2021/10/19"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/07/17"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/01/23"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/07/03"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/03"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/14"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/08/17"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2021/10/13"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/07/17"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2020/10/15"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/08/26"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/02/18"
|
||||
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/10"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/05/08"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2023/01/17"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/03/12"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/10/15"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2021/10/15"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/07/17"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/12/04"
|
||||
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/10"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2024/05/03"
|
||||
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/10"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -1,8 +1,10 @@
|
||||
[metadata]
|
||||
creation_date = "2020/12/03"
|
||||
integration = ["endpoint", "windows", "system"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/09/23"
|
||||
updated_date = "2024/09/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -1,8 +1,10 @@
|
||||
[metadata]
|
||||
creation_date = "2023/03/16"
|
||||
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/10"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/03/29"
|
||||
integration = ["windows", "system"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/01/31"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/02/22"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2021/01/04"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "development"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Skoetting"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/11/09"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2023/11/15"
|
||||
integration = ["system", "windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2022/08/17"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/07/17"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[transform]
|
||||
[[transform.osquery]]
|
||||
|
||||
@@ -2,7 +2,9 @@
|
||||
creation_date = "2020/08/14"
|
||||
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
|
||||
maturity = "production"
|
||||
updated_date = "2024/10/10"
|
||||
updated_date = "2024/10/28"
|
||||
min_stack_version = "8.14.0"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,8 +2,10 @@
|
||||
bypass_bbr_timing = true
|
||||
creation_date = "2020/08/18"
|
||||
integration = ["endpoint", "windows", "system"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/08/07"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,8 +2,10 @@
|
||||
bypass_bbr_timing = true
|
||||
creation_date = "2020/12/04"
|
||||
integration = ["endpoint", "windows"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/05/21"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,8 +2,10 @@
|
||||
bypass_bbr_timing = true
|
||||
creation_date = "2023/01/24"
|
||||
integration = ["windows", "endpoint", "system"]
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
maturity = "production"
|
||||
updated_date = "2024/09/23"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
@@ -2,9 +2,9 @@
|
||||
creation_date = "2023/07/12"
|
||||
integration = ["windows"]
|
||||
maturity = "production"
|
||||
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
|
||||
min_stack_version = "8.12.0"
|
||||
updated_date = "2024/03/12"
|
||||
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
|
||||
min_stack_version = "8.14.0"
|
||||
updated_date = "2024/10/28"
|
||||
|
||||
[rule]
|
||||
author = ["Elastic"]
|
||||
|
||||
Reference in New Issue
Block a user