Jonhnathan
|
5ec8e3e500
|
[Rule Tuning] Communication App Rules (#5487)
* [Rule Tuning] Communication App Rules
* Update defense_evasion_masquerading_business_apps_installer.toml
* Update defense_evasion_masquerading_business_apps_installer.toml
* Update defense_evasion_masquerading_communication_apps.toml
* Update defense_evasion_masquerading_business_apps_installer.toml
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
|
2025-12-18 02:38:18 -08:00 |
|
Jonhnathan
|
85a0d27b13
|
[Rule Tuning] Windows 3rd Party EDR Compatibility - Part 4 (#5019)
* [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 4
* Update rules/windows/defense_evasion_microsoft_defender_tampering.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
|
2025-08-28 11:05:42 -07:00 |
|
shashank-elastic
|
e4856d3c2c
|
Refresh ecs, beats, integration manifests & schemas (#4699)
|
2025-05-05 23:06:40 +05:30 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
shashank-elastic
|
e357a2c050
|
Refresh MITRE Attack v15.1.0 (#3725)
|
2024-06-04 20:14:58 +05:30 |
|
shashank-elastic
|
63e91c2f12
|
Back-porting Version Trimming (#3704)
|
2024-05-23 00:45:10 +05:30 |
|
Mika Ayenson
|
2c3dbfc039
|
Revert "Back-porting Version Trimming (#3681)"
This reverts commit 71d2c59b5c.
|
2024-05-22 13:51:46 -05:00 |
|
shashank-elastic
|
71d2c59b5c
|
Back-porting Version Trimming (#3681)
|
2024-05-23 00:11:50 +05:30 |
|
Jonhnathan
|
b47b91b9ec
|
[Rule Tuning] Tighten up Indexes of Elastic Defend Windows Rules (#3549)
* [Rule Tuning] Tighten up Indexes of Elastic Defend Windows Rules
* Delete test.pkl
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
|
2024-04-01 20:45:12 -03:00 |
|
Jonhnathan
|
6fcf26b20e
|
[Promote] Potential Masquerading as Communication Apps (#3181)
* [Promote] Potential Masquerading as Communication Apps
* Update defense_evasion_masquerading_communication_apps.toml
* Update defense_evasion_masquerading_communication_apps.toml
* Update rules/windows/defense_evasion_masquerading_communication_apps.toml
* Update defense_evasion_masquerading_communication_apps.toml
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
|
2023-10-23 14:56:03 -03:00 |
|