Ruben Groenewoud
|
578e86eeae
|
[Tuning] event.action and event.type change (#3495)
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Removed changes from:
- rules/linux/discovery_process_capabilities.toml
- rules/linux/privilege_escalation_enlightenment_window_manager.toml
- rules/linux/privilege_escalation_gdb_sys_ptrace_elevation.toml
- rules/linux/privilege_escalation_gdb_sys_ptrace_netcon.toml
- rules/linux/privilege_escalation_suspicious_chown_fowner_elevation.toml
- rules/linux/privilege_escalation_suspicious_uid_guid_elevation.toml
- rules_building_block/discovery_capnetraw_capability.toml
- rules_building_block/persistence_cap_sys_admin_added_to_new_binary.toml
(selectively cherry picked from commit 9f8638a004)
|
2024-03-13 09:16:15 +00:00 |
|
Jonhnathan
|
b1989a921b
|
[Security Content] Small tweaks on the setup guides (#3308)
* [Security Content] Small tweaks on the setup guides
* Additional Fixes
* Avoid touching deprecated rules
Removed changes from:
- rules/integrations/beaconing/command_and_control_beaconing.toml
- rules/integrations/beaconing/command_and_control_beaconing_high_confidence.toml
- rules/linux/discovery_process_capabilities.toml
- rules/linux/privilege_escalation_dac_permissions.toml
- rules/linux/privilege_escalation_enlightenment_window_manager.toml
- rules/linux/privilege_escalation_gdb_sys_ptrace_elevation.toml
- rules/linux/privilege_escalation_gdb_sys_ptrace_netcon.toml
- rules/linux/privilege_escalation_suspicious_chown_fowner_elevation.toml
- rules/linux/privilege_escalation_suspicious_uid_guid_elevation.toml
- rules_building_block/discovery_capnetraw_capability.toml
- rules_building_block/persistence_cap_sys_admin_added_to_new_binary.toml
(selectively cherry picked from commit 458e67918a)
|
2024-03-11 12:14:53 +00:00 |
|
Ruben Groenewoud
|
0950594b49
|
[Tuning] Linux DR Tuning - Part 7 (#3458)
* [Tuning] Linux DR Tuning - Part 7
* Update execution_potential_hack_tool_executed.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
(cherry picked from commit c537fb9c22)
|
2024-03-07 09:51:37 +00:00 |
|
Ruben Groenewoud
|
ee5fa810aa
|
[Tuning & New Rule] Linux Reverse Shell & DR Tuning (#3254)
* [Rule Tuning & New Rule] Linux Reverse Shell
* [Tuning & New Rule] Linux Reverse Shells
* Name change
* Update rules/linux/execution_shell_via_child_tcp_utility_linux.toml
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
* Update execution_shell_via_child_tcp_utility_linux.toml
* Update execution_shell_via_background_process.toml
---------
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
(cherry picked from commit 84824c67fd)
|
2023-12-18 08:41:02 +00:00 |
|
shashank-elastic
|
9c271c6591
|
Enhance Setup Guide information (#3256)
(cherry picked from commit d52546eee5)
|
2023-11-03 13:41:40 +00:00 |
|
shashank-elastic
|
60475f6aa0
|
Move Setup information into setup filed (#3206)
(cherry picked from commit 7254c582c5)
|
2023-10-23 14:04:26 +00:00 |
|
shashank-elastic
|
a7e83681e3
|
Setup information for Linux Rules - Set5 (#3188)
(cherry picked from commit 2a48db0598)
|
2023-10-17 13:46:52 +00:00 |
|
Ruben Groenewoud
|
bd7d94c1f3
|
[New Rule] Pot. Rev. Shell via Background Process (#3114)
(cherry picked from commit a46797b987)
|
2023-10-06 21:20:37 +00:00 |
|