Ruben Groenewoud
|
473df70fbb
|
[Rule Tuning] Linux DR Tuning - 5 (#5494)
* [Rule Tuning] Linux DR Tuning - 5
* Fix query syntax for shared object detection rule
* Update defense_evasion_kernel_module_removal.toml
* Fix condition for process working directory check
* Refactor query in defense_evasion_symlink_binary rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2026-01-07 15:55:06 +01:00 |
|
Ruben Groenewoud
|
be3af09d9d
|
[Rule Tuning] Misc. Linux Community Tunings (#5160)
* [Rule Tuning] Misc. Linux Community Tunings
* ++
* Fix query syntax in execution_unusual_path_invocation rule
* Refactor process.parent conditions for clarity
|
2025-10-06 12:05:59 +02:00 |
|
shashank-elastic
|
059d7efa25
|
Prep for Release 9.0 (#4550)
|
2025-03-20 20:32:07 +05:30 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Jonhnathan
|
282f613ddf
|
[Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 1 (#4330)
* [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 1
* min_stack
* Update defense_evasion_doas_configuration_creation_or_rename.toml
---------
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
|
2025-01-08 14:40:43 -03:00 |
|
Ruben Groenewoud
|
feaeabf60c
|
[New Rule] Dynamic Linker (ld.so) Creation (#4306)
|
2025-01-03 17:06:38 +01:00 |
|