Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Jonhnathan
|
63956a6f51
|
[Rule Tuning] 3rd Party EDR - Add Crowdstrike FDR support - 4 (#4225)
|
2024-11-05 14:22:14 -03:00 |
|
Jonhnathan
|
2c07e88c07
|
[Rule Tuning] Fix double bumps caused by Windows Integration Update (#4156)
|
2024-10-15 23:57:44 +05:30 |
|
Jonhnathan
|
32d02ae7aa
|
[Rule Tuning] 3rd Party EDR Compatibility - 11 (#4036)
* [Rule Tuning] 3rd Party EDR Compatibility - 11
* min_stack for merge, bump updated_date
|
2024-10-11 16:14:40 -03:00 |
|
Jonhnathan
|
f5069763b6
|
[Rule Tuning] Add System tag to DRs (#3968)
* [Rule Tuning] Add System tag to DRs
* bump
|
2024-08-09 11:14:33 -03:00 |
|
shashank-elastic
|
63e91c2f12
|
Back-porting Version Trimming (#3704)
|
2024-05-23 00:45:10 +05:30 |
|
Mika Ayenson
|
2c3dbfc039
|
Revert "Back-porting Version Trimming (#3681)"
This reverts commit 71d2c59b5c.
|
2024-05-22 13:51:46 -05:00 |
|
shashank-elastic
|
71d2c59b5c
|
Back-porting Version Trimming (#3681)
|
2024-05-23 00:11:50 +05:30 |
|
Jonhnathan
|
b47b91b9ec
|
[Rule Tuning] Tighten up Indexes of Elastic Defend Windows Rules (#3549)
* [Rule Tuning] Tighten up Indexes of Elastic Defend Windows Rules
* Delete test.pkl
---------
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
|
2024-04-01 20:45:12 -03:00 |
|
Samirbous
|
4809de6584
|
[New] Suspicious Execution from INET Cache (#3445)
* Create initial_access_execution_from_inetcache.toml
* Update initial_access_execution_from_inetcache.toml
|
2024-02-15 19:14:25 +00:00 |
|