Jonhnathan
|
85a9c7180d
|
[Rule Tuning] Windows Misc Tuning (#5382)
* [Rule Tuning] Windows Misc Tuning
* Update execution_suspicious_powershell_imgload.toml
* I need some coffee
|
2025-12-01 07:28:25 -08:00 |
|
shashank-elastic
|
e4856d3c2c
|
Refresh ecs, beats, integration manifests & schemas (#4699)
|
2025-05-05 23:06:40 +05:30 |
|
shashank-elastic
|
e8c54169a4
|
Prep main for 9.1 (#4555)
* Prep for Release 9.1
* Update Patch Version
* Update Patch version
* Update Patch version
|
2025-03-26 11:04:14 -04:00 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Jonhnathan
|
2c07e88c07
|
[Rule Tuning] Fix double bumps caused by Windows Integration Update (#4156)
|
2024-10-15 23:57:44 +05:30 |
|
Jonhnathan
|
e1addc6a8f
|
[Rule Tuning] 3rd Party EDR Compatibility - 18 (#4056)
* [Rule Tuning] 3rd Party EDR Compatibility - 18
* Update persistence_browser_extension_install.toml
* Update persistence_browser_extension_install.toml
* Update persistence_browser_extension_install.toml
* min_stack for merge, bump updated_date
* Update persistence_browser_extension_install.toml
|
2024-10-13 20:25:17 -03:00 |
|
Jonhnathan
|
07c4535871
|
[Rule Tuning] 3rd Party EDR Compatibility - 13 (#4038)
* [Rule Tuning] 3rd Party EDR Compatibility - 13
* min_stack for merge, bump updated_date
|
2024-10-11 16:55:02 -03:00 |
|
shashank-elastic
|
63e91c2f12
|
Back-porting Version Trimming (#3704)
|
2024-05-23 00:45:10 +05:30 |
|
Mika Ayenson
|
2c3dbfc039
|
Revert "Back-porting Version Trimming (#3681)"
This reverts commit 71d2c59b5c.
|
2024-05-22 13:51:46 -05:00 |
|
shashank-elastic
|
71d2c59b5c
|
Back-porting Version Trimming (#3681)
|
2024-05-23 00:11:50 +05:30 |
|
Jonhnathan
|
c2d1586270
|
[Rule Tuning] Windows BBR Promotion (#3577)
* [Rule Tuning] Windows BBR Promotion
* Update non-ecs-schema.json
* Update persistence_netsh_helper_dll.toml
* Update persistence_werfault_reflectdebugger.toml
* Update privilege_escalation_unquoted_service_path.toml
* Update defense_evasion_msdt_suspicious_diagcab.toml
* Update defense_evasion_suspicious_msiexec_execution.toml
* Update discovery_security_software_wmic.toml
* Revert "Update defense_evasion_msdt_suspicious_diagcab.toml"
This reverts commit 0e1f3ea3e18a146c421a5bda784633cca4a2b0c0.
* Revert "Update defense_evasion_suspicious_msiexec_execution.toml"
This reverts commit 4e26a167774ad712d19334a4c2c712cc1d550e7f.
* Revert "Update discovery_security_software_wmic.toml"
This reverts commit d638cec354a46cacab1e62596f4ad939a1d9c32a.
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
|
2024-04-16 09:28:17 -03:00 |
|