* remove timestamp_override from endgame promotion rules
* updated version.lock to previous state for endgame promotion rule changes
* fix incorrect year in updated_date
* update azure indicies
* remove . in index to match prior cloud rules
* update o365 indicies
* add event.dataset:google_workspace.admin to existing google workspace rules
* gcp syntax
* add gcp index
* update gcp index
* update index patterns for google workspace rules
* update gcp index2
* update updated_date
* update event outcome for azure
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
* [New Rule] O365 Exchange DKIM Signing Configuration Disabled
* rebrand to m365
* still req non ecs schema
* Remove the ECS override
* Update _flatten_schema logic
* Allow fields with * in the path
* Allow explicit fields to overwrite implicit * fields
Co-authored-by: Ross Wolf <31489089+rw-access@users.noreply.github.com>
* [New Rule] Attempts to Brute Force an O365 User Account
* Update credential_access_o365_brute_force_user_account_attempt.toml
* rebrand to m365
* Update credential_access_microsoft_365_brute_force_user_account_attempt.toml
* update description