github-actions[bot]
1dfb05ec1c
Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 ( #4442 )
2025-02-04 00:05:59 +05:30
shashank-elastic
a866ee7f57
Fix remaining Replace master doc URLs with current ( #4441 )
2025-02-03 23:03:20 +05:30
shashank-elastic
818467f132
Replace master doc URLs with current ( #4439 )
2025-02-03 21:27:50 +05:30
Samirbous
8f73b88884
[Tuning / New] Execution of a downloaded windows script ( #4434 )
...
* [New] Execution of a downloaded windows script
using 8.15 file events with MOTW info we can focus on js/vbs/wsh/vbe/jse/hta downloaded from internet followed by execution
* Update defense_evasion_posh_assembly_load.toml
* Update execution_powershell_susp_args_via_winscript.toml
* Update guides
* Update defense_evasion_network_connection_from_windows_binary.toml
* Update execution_windows_script_from_internet.toml
* Update execution_windows_script_from_internet.toml
* Update rules/windows/execution_windows_script_from_internet.toml
* Update rules/windows/execution_powershell_susp_args_via_winscript.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/windows/execution_windows_script_from_internet.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update execution_windows_script_from_internet.toml
* Create command_and_control_tool_transfer_via_curl.toml
* Update command_and_control_tool_transfer_via_curl.toml
* Update command_and_control_tool_transfer_via_curl.toml
* Update execution_windows_script_from_internet.toml
* Create defense_evasion_indirect_exec_forfiles.toml
* Update execution_windows_script_from_internet.toml
---------
Co-authored-by: Mika Ayenson <Mika.ayenson@elastic.co >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
2025-02-03 14:33:59 +00:00
shashank-elastic
aba793f3e5
Add prerelease version Integration manifests & schemas for sentinel_one_cloud_funnel ( #4438 )
2025-02-03 09:15:14 -05:00
shashank-elastic
350474b7b4
Refresh ECS & Beats schemas, Integration manifests & schemas ( #4436 )
2025-02-03 19:18:49 +05:30
Ruben Groenewoud
8d29a1f7d5
[New Rule] Process Backgrounded by Unusual Parent ( #4431 )
...
* [New Rule] Process Backgrounded by Unusual Parent
* Update execution_process_backgrounded_by_unusual_parent.toml
* Update execution_process_backgrounded_by_unusual_parent.toml
2025-02-03 14:17:15 +01:00
Ruben Groenewoud
14c648598e
[Rule Tuning] Linux DR Tuning - Part 6 ( #4423 )
...
* [Rule Tuning] Linux DR Tuning - Part 6
* Update privilege_escalation_ld_preload_shared_object_modif.toml
* Update privilege_escalation_ld_preload_shared_object_modif.toml
2025-02-03 14:05:26 +01:00
Ruben Groenewoud
6b84542093
[Rule Tuning] Linux DR Tuning - Part 5 ( #4422 )
...
* [Rule Tuning] Linux DR Tuning - Part 5
* Update rules/linux/persistence_xdg_autostart_netcon.toml
2025-02-03 13:53:53 +01:00
Ruben Groenewoud
53b9b53467
[Rule Tuning] Linux DR Tuning - Part 4 ( #4421 )
...
* [Rule Tuning] Linux DR Tuning - Part 4
* [Rule Tuning] Linux DR Tuning - Part 4
* Update persistence_etc_file_creation.toml
2025-02-03 13:31:00 +01:00
Ruben Groenewoud
1c98a0d64c
[Rule Tuning] Linux DR Tuning - Part 3 ( #4420 )
...
* Initial set
* [Rule Tuning] Linux DR - Part 3
* ++
* Update execution_unusual_path_invocation_from_command_line.toml
* Update execution_unusual_path_invocation_from_command_line.toml
2025-02-03 13:17:00 +01:00
Terrance DeJesus
bf1caf8b5f
[Rule Tuning] December-January AWS Rule Tuning ( #4425 )
...
* [Rule Tuning] AWS Monthly Rule Tunings
* Adding several more AWS tunings
* updating patch version
* updating non-ecs type to boolean
* fixed cloudtrail index
2025-01-31 10:35:18 -05:00
Ruben Groenewoud
b1a8341371
[Hunt Tuning] Logon Activity by Source IP ( #4428 )
2025-01-31 15:44:38 +01:00
Ruben Groenewoud
b642c55680
[Rule Tuning] Potential OpenSSH Backdoor Logging Activity ( #4429 )
2025-01-31 15:33:21 +01:00
Ruben Groenewoud
18dd9cb04a
[New Rule] Suspicious Usage of bpf_probe_write_user Helper ( #4426 )
...
* [New Rule] Suspicious Usage of bpf_probe_write_user Helper
* Update persistence_bpf_probe_write_user.toml
2025-01-29 11:46:40 +01:00
Ruben Groenewoud
52d33c12b8
[Rule Tuning] Linux DR Tuning - Part 2 ( #4417 )
2025-01-29 10:34:13 +01:00
Terrance DeJesus
4e95bc7891
[New Hunt] Adding Hunting Query for IAM Unusual Default Aviatrix Role Activity ( #4409 )
...
* new hunt 'unusual aviatrix default role activity'
* added additional investigation notes
2025-01-28 12:09:29 -05:00
Ruben Groenewoud
fed7b216d5
[Rule Tuning] Linux DR Tuning - Part 1 ( #4416 )
2025-01-28 14:43:00 +01:00
Ruben Groenewoud
bbcf0c7c34
[New Hunt] Persistence via Initramfs ( #4402 )
...
* [New Hunt] Persistence via Initramfs
* Update index.yml
2025-01-27 10:19:44 +01:00
Ruben Groenewoud
80fe96109b
[New & Tuning] Persistence via GRUB Bootloader ( #4401 )
...
* [New & Tuning] Persistence via GRUB Bootloader
* testing github version code workflow update
* testing github version code workflow re-order
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
2025-01-27 09:58:43 +01:00
Samirbous
4e6625ae40
[Tuning] Unusual Instance Metadata Service (IMDS) API Request ( #4418 )
...
* Update credential_access_unusual_instance_metadata_service_api_request.toml
* Update credential_access_unusual_instance_metadata_service_api_request.toml
* Update credential_access_unusual_instance_metadata_service_api_request.toml
* Update rules/linux/credential_access_unusual_instance_metadata_service_api_request.toml
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2025-01-24 17:23:32 +00:00
Jonhnathan
fccfafea6b
[Rule Tuning] Improve Detection Compatibility with Non-English Logs ( #4410 )
...
* [Rule Tuning] Improve Detection Compatibility with Non-English Logs
* Update rules/windows/persistence_dontexpirepasswd_account.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Update credential_access_disable_kerberos_preauth.toml
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2025-01-23 16:12:42 -03:00
shashank-elastic
d6f1a75f11
Fix S1 minstack version ( #4415 )
2025-01-23 17:59:40 +05:30
Mika Ayenson
7c6c77932c
[FR] Add Remaining Guides ( #4412 )
2025-01-22 14:43:30 -06:00
Mika Ayenson
fe8c81d762
[FR] Generate investigation guides ( #4358 )
2025-01-22 11:17:38 -06:00
Jonhnathan
d55d5d9695
[New Rule] File with Right-to-Left Override Character Created/Executed ( #4396 )
...
* [New Rule] File with Right-to-Left Override Character Created/Executed
* Update defense_evasion_right_to_left_override.toml
* Update defense_evasion_right_to_left_override.toml
2025-01-21 16:41:49 -03:00
github-actions[bot]
8093655f76
Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 ( #4400 )
2025-01-21 19:35:57 +05:30
github-actions[bot]
9b8b917598
Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md ( #4398 )
2025-01-21 17:32:14 +05:30
Ruben Groenewoud
b708e09f2b
[New Rule] Unusual D-Bus Daemon Child Process ( #4397 )
2025-01-21 12:24:06 +01:00
Terrance DeJesus
fb13b89f8d
[New Rule] Adding Coverage for AWS S3 Unauthenticated Bucket Access by Rare Source ( #4315 )
...
* adding new rule 'AWS S3 Unauthenticated Object Retrieval by Rare Source'
* adjusted logic to capture multiple event calls
* updated verbiage
* updated MITRE mappings
* fixing date
2025-01-20 13:36:09 -05:00
Terrance DeJesus
7be96ec64d
[Rule Tuning] Add Public Snapshot Coverage Regarding AWS EC2 EBS Snapshot Shared or Made Public ( #4335 )
...
* removing detection gap for EBS snapshots that are made public
* reverted logic; added investigation note about public snapshots
2025-01-20 13:15:41 -05:00
Ruben Groenewoud
cf183579b4
[New Rule] Polkit Version Discovery ( #4378 )
2025-01-20 15:58:27 +01:00
Ruben Groenewoud
2e6ec33141
[New Rule] Polkit Policy Creation ( #4379 )
...
* [New Rule] Polkit Policy Creation
* Update persistence_polkit_policy_creation.toml
2025-01-20 15:47:18 +01:00
Ruben Groenewoud
3e655abfef
[New Rule] Unusual Pkexec Execution ( #4380 )
...
* [New Rule] Unusual Pkexec Execution
* Update execution_unusual_pkexec_execution.toml
2025-01-20 15:35:29 +01:00
Ruben Groenewoud
4294ed8981
[New Rule] NetworkManager Dispatcher Script Creation ( #4381 )
...
* [New Rule] NetworkManager Dispatcher Script Creation
* ++
2025-01-20 15:18:55 +01:00
Ruben Groenewoud
89c113560b
[New Rule] D-Bus Service Created ( #4382 )
2025-01-20 15:07:06 +01:00
Ruben Groenewoud
6cc5184f70
[New Rule] Manual Dracut Execution ( #4383 )
2025-01-20 14:41:44 +01:00
Ruben Groenewoud
abd199a9bc
[New Rule] Dracut Module Creation ( #4384 )
2025-01-20 14:31:16 +01:00
Ruben Groenewoud
2bb46899ae
[New Rule] OpenSSL Password Hash Generation ( #4385 )
...
* [New Rule] OpenSSL Password Hash Generation
* Update rules/linux/persistence_openssl_passwd_hash_generation.toml
2025-01-20 14:14:12 +01:00
Ruben Groenewoud
1fce3fd22a
[New Rule] Boot File Copy ( #4386 )
...
* [New Rule] Boot File Copy
* Update persistence_boot_file_copy.toml
* Update rules/linux/persistence_boot_file_copy.toml
2025-01-20 14:04:02 +01:00
Ruben Groenewoud
b633987e5b
[New Rule] Initramfs Unpacking via unmkinitramfs ( #4387 )
...
* [New Rule] Initramfs Unpacking via unmkinitramfs
* Update rules/linux/persistence_unpack_initramfs_via_unmkinitramfs.toml
2025-01-20 13:43:54 +01:00
Ruben Groenewoud
971049957e
[New Rule] Initramfs Extraction via CPIO ( #4389 )
...
* [New Rule] Initramfs Extraction via CPIO
* Update rules/linux/persistence_extract_initramfs_via_cpio.toml
2025-01-20 13:32:48 +01:00
Samirbous
1dfc84c37d
[Tuning] Powershell Rules ( #4395 )
...
* [Tuning] Powershell Rules
few complementary tuning to add some extra patterns.
* Update defense_evasion_amsi_bypass_powershell.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2025-01-20 12:12:37 +00:00
Ruben Groenewoud
01eda44298
[Rule Tuning] Linux Persistence Rules ( #4393 )
...
* [Rule Tuning] Linux Persistence Rules
* Update persistence_suspicious_file_modifications.toml
* Update rules/linux/persistence_potential_persistence_script_executable_bit_set.toml
2025-01-20 09:51:49 +01:00
Ruben Groenewoud
cf929554a6
[New Rule] Systemd Shell Execution During Boot ( #4392 )
2025-01-20 09:33:46 +01:00
Eric Forte
2ea674ce84
[Bug] [DaC] Metadata maturity field default mismatch and poor enforcement of rule naming conventions ( #4285 )
...
* Add stub for solution
* Add date and maturity logic
* Add date and maturity logic
* Version Bump
* Remove Date Inheritance
* Remove Datetime import
2025-01-17 12:16:32 -05:00
Ruben Groenewoud
f029e9a171
[New Rule] GRUB Configuration Generation through Built-in Utilities ( #4391 )
2025-01-17 18:00:01 +01:00
Ruben Groenewoud
0ef7f3a83e
[New Rule] GRUB Configuration File Creation ( #4390 )
...
* [New Rule] Grub Configuration File Creation
* Update persistence_grub_configuration_creation.toml
2025-01-17 17:49:41 +01:00
Ruben Groenewoud
28c3d074b8
[New Rule] Process Started with Executable Stack ( #4340 )
...
* [New Rule] Process Started with Executable Stack
* [New Rule] Process Started with Executable Stack
* Update execution_executable_stack_execution.toml
* Update rules/linux/execution_executable_stack_execution.toml
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2025-01-17 17:36:39 +01:00
Terrance DeJesus
ca3994af0d
[Deprecation] Deprecating Potential Password Spraying of Microsoft 365 User Accounts ( #4394 )
...
* Deprecating 'Potential Password Spraying of Microsoft 365 User Accounts'
* adding 'Deprecated - Suspicious JAVA Child Process'
* updated dates
* changed to deprecated maturity
2025-01-17 10:52:13 -05:00