Samirbous
|
34bd88a37e
|
[Tuning] Potential Ransomware Behavior - Note Files by System (#5235)
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update rules/windows/impact_high_freq_file_renames_by_kernel.toml
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
|
2025-11-10 18:22:37 +00:00 |
|
Samirbous
|
66a0b6b97c
|
[Tuning] Potential Ransomware Behavior - High count of Readme files by System (#5167)
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
|
2025-10-02 17:39:51 +01:00 |
|
Jonhnathan
|
7bd9c52852
|
[Rule Tuning] Windows High Severity - 5 (#5096)
* [Rule Tuning] Windows High Severity - 4
* Update privilege_escalation_windows_service_via_unusual_client.toml
|
2025-09-15 09:29:37 -07:00 |
|
shashank-elastic
|
e8c54169a4
|
Prep main for 9.1 (#4555)
* Prep for Release 9.1
* Update Patch Version
* Update Patch version
* Update Patch version
|
2025-03-26 11:04:14 -04:00 |
|
shashank-elastic
|
92fe46b8ff
|
Fix Minstack version for windows integration (#4214)
|
2024-10-28 19:28:10 +05:30 |
|
Jonhnathan
|
e1addc6a8f
|
[Rule Tuning] 3rd Party EDR Compatibility - 18 (#4056)
* [Rule Tuning] 3rd Party EDR Compatibility - 18
* Update persistence_browser_extension_install.toml
* Update persistence_browser_extension_install.toml
* Update persistence_browser_extension_install.toml
* min_stack for merge, bump updated_date
* Update persistence_browser_extension_install.toml
|
2024-10-13 20:25:17 -03:00 |
|
Samirbous
|
603f3c313a
|
Update impact_high_freq_file_renames_by_kernel.toml (#3707)
|
2024-05-23 17:59:58 +01:00 |
|
shashank-elastic
|
63e91c2f12
|
Back-porting Version Trimming (#3704)
|
2024-05-23 00:45:10 +05:30 |
|
Mika Ayenson
|
2c3dbfc039
|
Revert "Back-porting Version Trimming (#3681)"
This reverts commit 71d2c59b5c.
|
2024-05-22 13:51:46 -05:00 |
|
shashank-elastic
|
71d2c59b5c
|
Back-porting Version Trimming (#3681)
|
2024-05-23 00:11:50 +05:30 |
|
Samirbous
|
4a2e2764cd
|
[New] Ransomware over SMB (#3638)
* [New] Ransomware over SMB
* Update impact_ransomware_note_file_over_smb.toml
* Update impact_ransomware_file_rename_smb.toml
* ++
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_high_freq_file_renames_by_kernel.toml
* Update impact_ransomware_file_rename_smb.toml
* Update impact_ransomware_note_file_over_smb.toml
* Update impact_high_freq_file_renames_by_kernel.toml
|
2024-05-07 06:38:14 +01:00 |
|