Mika Ayenson, PhD
|
8993d1450b
|
[Rule Tuning] Add Supplemental Mitre Mappings (#5876)
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>
|
2026-04-01 09:12:42 -05:00 |
|
Ruben Groenewoud
|
019c263ed2
|
[Rule Tuning] Linux DR Tuning - 1 (#5122)
* [Rule Tuning] Linux DR Tuning - 1
* Added integrations
* Update command_and_control_git_repo_or_file_download_to_sus_dir.toml
* Update collection_linux_clipboard_activity.toml
* Update collection_linux_clipboard_activity.toml
* Update rules/linux/command_and_control_aws_cli_endpoint_url_used.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Update collection_linux_clipboard_activity.toml
* Update rules/linux/command_and_control_aws_cli_endpoint_url_used.toml
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
|
2026-01-06 16:18:04 +01:00 |
|
Jonhnathan
|
0268daa17d
|
[Rule Tuning] Tighten Up Elastic Defend Indexes - Linux (#4446)
|
2025-02-05 15:25:45 -03:00 |
|
Mika Ayenson
|
fe8c81d762
|
[FR] Generate investigation guides (#4358)
|
2025-01-22 11:17:38 -06:00 |
|
Ruben Groenewoud
|
993c60decb
|
[New Rule] Curl SOCKS Proxy Activity from Unusual Parent (#4237)
* [New Rule] Curl SOCKS Proxy Activity from Unusual Parent
* OS Type update
* Update rules/linux/command_and_control_curl_socks_proxy_detected.toml
---------
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
|
2024-11-08 16:51:18 +01:00 |
|