Terrance DeJesus
|
deab1c0161
|
[Rule Tuning] Change event.dataset to data_stream.dataset (#5943)
* [Rule Tuning] Change event.dataset to data_stream.dataset
* updating ESQL field names
|
2026-04-10 12:27:52 -04:00 |
|
Mika Ayenson, PhD
|
8993d1450b
|
[Rule Tuning] Add Supplemental Mitre Mappings (#5876)
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>
|
2026-04-01 09:12:42 -05:00 |
|
Ruben Groenewoud
|
612928b34c
|
[Rule Tuning] Potential Persistence via File Modification (#5404)
|
2025-12-05 10:32:58 +01:00 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Ruben Groenewoud
|
01eda44298
|
[Rule Tuning] Linux Persistence Rules (#4393)
* [Rule Tuning] Linux Persistence Rules
* Update persistence_suspicious_file_modifications.toml
* Update rules/linux/persistence_potential_persistence_script_executable_bit_set.toml
|
2025-01-20 09:51:49 +01:00 |
|
Ruben Groenewoud
|
466097c31e
|
[Rule Tuning] Potential Persistence via File Modification (#4310)
* [Rule Tuning] Potential Persistence via File Modification
* Update persistence_suspicious_file_modifications.toml
* Update persistence_suspicious_file_modifications.toml
|
2025-01-03 16:19:58 +01:00 |
|
Mika Ayenson
|
b80d8342d6
|
[Docs | Rule Tuning] Add blog references to rules (#4097)
* [Docs | Rule Tuning] Add blog references to rules
* Apply suggestions from code review
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Apply suggestions from code review
* Update google_workspace blog references
* add okta blog references
* Update dates
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
|
2024-09-25 15:19:20 -05:00 |
|
Ruben Groenewoud
|
21485b16fa
|
[Tuning & Changes] Misc rule/hunt tuning (#3875)
* [Tuning & Changes] Misc rule/hunt tuning
* Bump update_date
* ++
* Updated docs
|
2024-07-11 14:55:33 +02:00 |
|
shashank-elastic
|
89d89f15d2
|
Update FIM integration Setup sequence (#3781)
|
2024-06-12 16:40:45 +05:30 |
|
Ruben Groenewoud
|
ec223a4a05
|
[New Rule] Suspicious File Modification (#3746)
* [New Rule] Suspicious File Modification
* Update persistence_suspicious_file_modifications.toml
* Update rules/linux/persistence_suspicious_file_modifications.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Update rules/linux/persistence_suspicious_file_modifications.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Updates
* Update rules/integrations/fim/persistence_suspicious_file_modifications.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com>
|
2024-06-11 13:03:20 +02:00 |
|