Justin Ibarra
6bdfddac8e
Expand timestamp override tests ( #1907 )
...
* Expand timestamp_override tests
* removed timestamp_override from eql sequence rules
* add config entry for eql rules with beats index and t_o
* add timestamp_override to missing fields
2022-04-01 15:27:08 -08:00
Justin Ibarra
3fc34b86f2
Update License to Elastic v2 ( #944 )
2021-03-03 22:12:11 -09:00
Justin Ibarra
645a0cd67b
[Rule Tuning] Add timestamp_override to all query and non-sequence EQL rules ( #945 )
...
* [Rule Tuning] Add timestamp_override field to rules
* add tests for lookback and timestamp_override
* fix dates and add test to ensure updated > creation
2021-02-17 19:49:58 -09:00
Samirbous
497ddcbb58
[New Rule] Suspicious Python Script Execution via the CommandLine ( #852 )
...
* [New Rule] Suspicious Python Script Execution via the CommandLine
* kql optimz
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
* added subtechnique
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
* converted to eql
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
* relinted
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
2021-02-10 18:37:03 +01:00