Ruben Groenewoud
|
c2747b0b29
|
[Rule Tuning] Linux DR Tuning - 4 (#5484)
* [Rule Tuning] Linux DR Tuning - 4
* Update defense_evasion_file_mod_writable_dir.toml
* Update command_and_control_frequent_egress_netcon_from_sus_executable.toml
* Remove duplicate host.name entry in TOML file
* Fix formatting in defense_evasion_file_mod_writable_dir.toml
* Update command_and_control_frequent_egress_netcon_from_sus_executable.toml
* Add additional fields to base64 decoding activity rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2026-01-08 10:11:05 +01:00 |
|
shashank-elastic
|
059d7efa25
|
Prep for Release 9.0 (#4550)
|
2025-03-20 20:32:07 +05:30 |
|
Jonhnathan
|
0268daa17d
|
[Rule Tuning] Tighten Up Elastic Defend Indexes - Linux (#4446)
|
2025-02-05 15:25:45 -03:00 |
|
Ruben Groenewoud
|
fed7b216d5
|
[Rule Tuning] Linux DR Tuning - Part 1 (#4416)
|
2025-01-28 14:43:00 +01:00 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Jonhnathan
|
cc889e3bf2
|
[Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 4 (#4345)
* [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 4
* Apply suggestions from code review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
|
2025-01-09 10:59:32 -03:00 |
|
Ruben Groenewoud
|
601254488b
|
[BBR Promotion] Q2 Linux BBR Promotion (#4172)
* [BBR Promotion] Q2 Linux BBR Promotion
* Update collection_linux_clipboard_activity.toml
* Update defense_evasion_creation_of_hidden_files_directories.toml
|
2024-10-18 16:55:09 +02:00 |
|