Jonhnathan
|
782605ae07
|
[Rule Tuning] PowerShell Windows Defender ATP DataCollection Scripts (#4867)
* [Rule Tuning] PowerShell Windows Defender ATP DataCollection Scripts
* bum updated_date
* Fix DSL exception
|
2025-07-07 10:56:13 -03:00 |
|
shashank-elastic
|
e8c54169a4
|
Prep main for 9.1 (#4555)
* Prep for Release 9.1
* Update Patch Version
* Update Patch version
* Update Patch version
|
2025-03-26 11:04:14 -04:00 |
|
Jonhnathan
|
74f11dbf7f
|
[Rule Tuning] Posh BBRs (#4372)
|
2025-01-15 11:00:21 -03:00 |
|
shashank-elastic
|
123e090e7d
|
Fix Minstack version for windows integration - Pahse 2 (#4216)
|
2024-10-28 20:25:02 +05:30 |
|
Jonhnathan
|
1bc59bdc04
|
[Rule Tuning] Windows BBR Rule Tuning - 2 (#3580)
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
|
2024-04-08 09:34:26 -03:00 |
|
Jonhnathan
|
67ca13c1ce
|
[Rule Tuning] Replace KQL exceptions for Query DSL Exceptions (#3505)
* [Rule Tuning] Replace KQL exceptions for Query DSL Exceptions
* update min_stack
* build out schema in more detail for Filters
* Update detection_rules/rule.py
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com>
* Remove enum for definition
* remove unused import
* remove $state store
* transform state
* add call to super
* add return type hint
* use dataclass metadata
* use Literal type
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
Co-authored-by: Mika Ayenson <Mika.ayenson@elastic.co>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com>
|
2024-04-01 17:44:50 -03:00 |
|
Jonhnathan
|
f5254f3b5e
|
[Rule Tuning] Improve Compatibility in WIndows Detection Rules - Part 1 (#3501)
* Initial commit
* Date bump
|
2024-03-13 10:27:44 -03:00 |
|
Jonhnathan
|
458e67918a
|
[Security Content] Small tweaks on the setup guides (#3308)
* [Security Content] Small tweaks on the setup guides
* Additional Fixes
* Avoid touching deprecated rules
|
2024-03-11 09:09:40 -03:00 |
|
Jonhnathan
|
1a8271db2f
|
[Rule Tuning] Windows BBR Tuning - 4 (#3384)
* [Rule Tuning] Windows BBR Tuning - 4
* Update discovery_system_time_discovery.toml
|
2024-02-14 14:21:07 -03:00 |
|
shashank-elastic
|
a568c56bc1
|
Move Config Guides for Pre-Built Detection Rules to Setup Field - Windows, MacOS, BBR and Cross Platform (#3157)
|
2023-10-30 16:53:04 +05:30 |
|
Jonhnathan
|
3f2a709370
|
[Rule Tuning] PowerShell Rules Tuning (#3169)
|
2023-10-11 17:57:32 -03:00 |
|
Jonhnathan
|
17f6537e44
|
[Rule Tuning] Windows BBR Rules (#3018)
* [Rule Tuning] Windows BBR Rules
* Update discovery_generic_process_discovery.toml
|
2023-08-25 05:21:16 -03:00 |
|
Mika Ayenson
|
3813a08f59
|
[FR] Add support for BBR rules to the rule loader (#2968)
---------
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>
|
2023-07-27 11:27:04 -05:00 |
|
Jonhnathan
|
7949b8a03e
|
[New Rule] Building Block Rules - Part 1 (#2912)
* [New Rule] Building Block Rules - Part 1
* Update defense_evasion_powershell_clear_logs_script.toml
* Update discovery_posh_generic.toml
* .
* Apply suggestions from code review
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
|
2023-07-18 20:01:43 -03:00 |
|