* win folder * Other folders * Update test_all_rules.py * . * updated missing elastic defend tags --------- Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
* [Rule Tuning] 2 tunings to reduce FPs back to 0 * Added one more tune for community issue #3041 * Update rules/linux/execution_abnormal_process_id_file_created.toml * Update rules/linux/execution_abnormal_process_id_file_created.toml
* [New Rule] Potential DebugFS Privilege Escalation * Changed rule name * Update rules/linux/privilege_escalation_sda_disk_mount_non_root.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>