Ruben Groenewoud
|
473df70fbb
|
[Rule Tuning] Linux DR Tuning - 5 (#5494)
* [Rule Tuning] Linux DR Tuning - 5
* Fix query syntax for shared object detection rule
* Update defense_evasion_kernel_module_removal.toml
* Fix condition for process working directory check
* Refactor query in defense_evasion_symlink_binary rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2026-01-07 15:55:06 +01:00 |
|
shashank-elastic
|
059d7efa25
|
Prep for Release 9.0 (#4550)
|
2025-03-20 20:32:07 +05:30 |
|
Ruben Groenewoud
|
52d33c12b8
|
[Rule Tuning] Linux DR Tuning - Part 2 (#4417)
|
2025-01-29 10:34:13 +01:00 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Jonhnathan
|
d6ceb88558
|
[Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 6 (#4348)
|
2025-01-09 10:17:57 -03:00 |
|
Ruben Groenewoud
|
3982228132
|
[Rule Tuning] Q2 Linux DR Tuning - Part 2 (#4163)
|
2024-10-18 16:07:09 +02:00 |
|
Ruben Groenewoud
|
9f964b68a4
|
[New Rule] Root Certificate Installation (#4025)
* [New Rule] Root Certificate Installation
* Update defense_evasion_root_certificate_installation.toml
* Update rules/linux/defense_evasion_root_certificate_installation.toml
|
2024-09-03 17:40:17 +02:00 |
|