shashank-elastic
|
123e090e7d
|
Fix Minstack version for windows integration - Pahse 2 (#4216)
|
2024-10-28 20:25:02 +05:30 |
|
shashank-elastic
|
275c7288a3
|
Add testcase to check for related_integrations based on index (#4096)
|
2024-10-22 00:17:30 +05:30 |
|
Jonhnathan
|
f5069763b6
|
[Rule Tuning] Add System tag to DRs (#3968)
* [Rule Tuning] Add System tag to DRs
* bump
|
2024-08-09 11:14:33 -03:00 |
|
Jonhnathan
|
25ad765acb
|
[Rule Tuning] Include winlogbeat index in sysmon-related rules (#3966)
|
2024-08-08 12:02:23 -03:00 |
|
Jonhnathan
|
125084ceec
|
[Rule Tuning] Improve Compatibility in WIndows BBR Detection Rules (#3841)
* [Rule Tuning] Improve Windows BBR Compatibility
* Update defense_evasion_services_exe_path.toml
|
2024-07-01 10:41:00 -03:00 |
|
shashank-elastic
|
63e91c2f12
|
Back-porting Version Trimming (#3704)
|
2024-05-23 00:45:10 +05:30 |
|
Mika Ayenson
|
2c3dbfc039
|
Revert "Back-porting Version Trimming (#3681)"
This reverts commit 71d2c59b5c.
|
2024-05-22 13:51:46 -05:00 |
|
shashank-elastic
|
71d2c59b5c
|
Back-porting Version Trimming (#3681)
|
2024-05-23 00:11:50 +05:30 |
|
Jonhnathan
|
109e8a85a5
|
[Rule Tuning] BBR Rule Tuning 1 - Tighten Indexes Edition (#3576)
* [Rule Tuning] BBR Rule Tuning 1 - Tighten Indexes Edition
* Apply suggestions from code review
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Update defense_evasion_msdt_suspicious_diagcab.toml
* Update defense_evasion_suspicious_msiexec_execution.toml
* Update discovery_security_software_wmic.toml
* Update rules_building_block/discovery_security_software_wmic.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Endgame tag
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
|
2024-04-08 08:57:33 -03:00 |
|
Jonhnathan
|
8049c96281
|
[New Rule] New BBR Rules - Part 1 (#3026)
* [New Rule] New BBR Rules - Part 1
* Apply suggestions from code review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
* Update rules_building_block/lateral_movement_at.toml
* Update rules_building_block/collection_outlook_email_archive.toml
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com>
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com>
|
2023-09-05 18:07:47 -03:00 |
|