Commit Graph

  • e7fd90f2b1 [FR] Update Validate Integrations to Check Fields Across All Schema Variations (#3372) Mika Ayenson 2024-01-18 15:42:22 -06:00
  • a873abbb5b [FR] Update Validate Integrations to Check Fields Across All Schema Variations (#3372) Mika Ayenson 2024-01-18 15:42:22 -06:00
  • 8a2475b5e3 Linux Process Capabilities Enrichment Detection Rules (#3366) shashank-elastic 2024-01-18 22:49:43 +05:30
  • 1a2ef4b867 Linux Process Capabilities Enrichment Detection Rules (#3366) shashank-elastic 2024-01-18 22:49:43 +05:30
  • 7367f37584 [Rule Tuning] Update timestamp_override Unit Tests and Fix Rules Missing Field (#3368) Terrance DeJesus 2024-01-17 14:14:38 -05:00
  • 869988c20f [Rule Tuning] Update timestamp_override Unit Tests and Fix Rules Missing Field (#3368) Terrance DeJesus 2024-01-17 14:14:38 -05:00
  • 1c10c37468 [Rule Tuning] Update timestamp_override Unit Tests and Fix Rules Missing Field (#3368) Terrance DeJesus 2024-01-17 14:14:38 -05:00
  • 652acc0f07 [Rule Tuning] Windows DR Tuning - 12 (#3364) Jonhnathan 2024-01-17 13:19:12 -03:00
  • 11c929f019 [Rule Tuning] Windows DR Tuning - 12 (#3364) Jonhnathan 2024-01-17 13:19:12 -03:00
  • f6ba12a700 [Rule Tuning] Windows DR Tuning - 12 (#3364) Jonhnathan 2024-01-17 13:19:12 -03:00
  • 5d9277280c [Tuning] Add logs-system. index where applicable (#3390) sbousseaden 2024-01-17 13:49:59 +00:00
  • c6725b5642 [Tuning] Add logs-system. index where applicable (#3390) sbousseaden 2024-01-17 13:49:59 +00:00
  • 27262a585b [Tuning] Add logs-system. index where applicable (#3390) sbousseaden 2024-01-17 13:49:59 +00:00
  • d73da3d1d5 [Rule Tuning] Windows DR Tuning - 13 (#3369) Jonhnathan 2024-01-17 09:53:18 -03:00
  • 91ee5caf94 [Rule Tuning] Windows DR Tuning - 13 (#3369) Jonhnathan 2024-01-17 09:53:18 -03:00
  • 71cec2a0e1 [Rule Tuning] Windows DR Tuning - 13 (#3369) Jonhnathan 2024-01-17 09:53:18 -03:00
  • 345298fe4f [Rule Tuning] Windows DR Tuning - 10 (#3355) Jonhnathan 2024-01-17 09:44:10 -03:00
  • b1c8876c53 [Rule Tuning] Windows DR Tuning - 10 (#3355) Jonhnathan 2024-01-17 09:44:10 -03:00
  • c6ab294627 [Rule Tuning] Windows DR Tuning - 10 (#3355) Jonhnathan 2024-01-17 09:44:10 -03:00
  • 5601eadfc1 [New Rule] Network Connection via Sudo Binary (#3389) Ruben Groenewoud 2024-01-17 09:47:58 +01:00
  • bf71869f01 [New Rule] Network Connection via Sudo Binary (#3389) Ruben Groenewoud 2024-01-17 09:47:58 +01:00
  • 4301dacfb8 [New Rule] Network Connection via Sudo Binary (#3389) Ruben Groenewoud 2024-01-17 09:47:58 +01:00
  • e7c4eb743a [New Rule] Kernel Driver Load by non-root User (#3378) Ruben Groenewoud 2024-01-17 09:34:25 +01:00
  • ab977df20d [New Rule] Kernel Driver Load by non-root User (#3378) Ruben Groenewoud 2024-01-17 09:34:25 +01:00
  • a9285445cf [New Rule] Kernel Driver Load by non-root User (#3378) Ruben Groenewoud 2024-01-17 09:34:25 +01:00
  • 15e3f1866e [Rule Tuning] Windows DR Tuning - 14 (#3376) Jonhnathan 2024-01-15 11:16:04 -03:00
  • 753578f336 [Rule Tuning] Windows DR Tuning - 14 (#3376) Jonhnathan 2024-01-15 11:16:04 -03:00
  • 0469785793 [Rule Tuning] Windows DR Tuning - 14 (#3376) Jonhnathan 2024-01-15 11:16:04 -03:00
  • d281983b99 [Rule Tuning] Windows DR Tuning - 11 (#3359) Jonhnathan 2024-01-15 10:55:50 -03:00
  • 336dba7d05 [Rule Tuning] Windows DR Tuning - 11 (#3359) Jonhnathan 2024-01-15 10:55:50 -03:00
  • caf38fd1b1 [Rule Tuning] Windows DR Tuning - 11 (#3359) Jonhnathan 2024-01-15 10:55:50 -03:00
  • 8c2415c00b Linux Rule Tuning (#3379) shashank-elastic 2024-01-11 18:07:03 +05:30
  • 3302d03900 Linux Rule Tuning (#3379) shashank-elastic 2024-01-11 18:07:03 +05:30
  • 24d5528ab0 Linux Rule Tuning (#3379) shashank-elastic 2024-01-11 18:07:03 +05:30
  • 968814ddbb [FR] Update _event_sort to use datetime instead of time (#3375) Eric Forte 2024-01-09 10:59:01 -05:00
  • 0afe7715f0 [FR] Update _event_sort to use datetime instead of time (#3375) Eric Forte 2024-01-09 10:59:01 -05:00
  • 6170db6231 [FR] Update _event_sort to use datetime instead of time (#3375) Eric Forte 2024-01-09 10:59:01 -05:00
  • 2f8ce915ab [Rule Tuning] Dynamic Linker Copy (#3349) Ruben Groenewoud 2024-01-08 10:56:31 +01:00
  • 19c6cbf075 [Rule Tuning] Dynamic Linker Copy (#3349) Ruben Groenewoud 2024-01-08 10:56:31 +01:00
  • df86882036 [Rule Tuning] Dynamic Linker Copy (#3349) Ruben Groenewoud 2024-01-08 10:56:31 +01:00
  • 4e20602c4c [Rule Tuning] Linux cross-platform DRs (#3346) Ruben Groenewoud 2024-01-08 10:44:03 +01:00
  • 14faea2175 [Rule Tuning] Linux cross-platform DRs (#3346) Ruben Groenewoud 2024-01-08 10:44:03 +01:00
  • 788e2b2823 [Rule Tuning] Linux cross-platform DRs (#3346) Ruben Groenewoud 2024-01-08 10:44:03 +01:00
  • f3273f1dac [Rule Tuning] Linux DR Tuning - Part 3 (#3322) Ruben Groenewoud 2024-01-08 10:16:44 +01:00
  • e95745664f [Rule Tuning] Linux DR Tuning - Part 3 (#3322) Ruben Groenewoud 2024-01-08 10:16:44 +01:00
  • 6c91c1597d [Rule Tuning] Linux DR Tuning - Part 3 (#3322) Ruben Groenewoud 2024-01-08 10:16:44 +01:00
  • 78618a1191 [Rule Tuning] Linux DR Tuning - Part 2 (#3321) Ruben Groenewoud 2024-01-08 10:07:38 +01:00
  • 629e4475f1 [Rule Tuning] Linux DR Tuning - Part 2 (#3321) Ruben Groenewoud 2024-01-08 10:07:38 +01:00
  • 36226e5428 [Rule Tuning] Linux DR Tuning - Part 2 (#3321) Ruben Groenewoud 2024-01-08 10:07:38 +01:00
  • 9017653e37 [Rule Tuning] Linux DR Tuning - Part 1 (#3316) Ruben Groenewoud 2024-01-08 09:50:15 +01:00
  • db58d0c5f2 [Rule Tuning] Linux DR Tuning - Part 1 (#3316) Ruben Groenewoud 2024-01-08 09:50:15 +01:00
  • b533642272 [Rule Tuning] Linux DR Tuning - Part 1 (#3316) Ruben Groenewoud 2024-01-08 09:50:15 +01:00
  • e22cc8030e [Rule Tuning] Windows DR Tuning - 9 (#3354) Jonhnathan 2024-01-07 09:49:33 -03:00
  • d435ab7c44 [Rule Tuning] Windows DR Tuning - 9 (#3354) Jonhnathan 2024-01-07 09:49:33 -03:00
  • 724e34ba95 [Rule Tuning] Windows DR Tuning - 9 (#3354) Jonhnathan 2024-01-07 09:49:33 -03:00
  • 92ed682a51 [Tuning] Update min_stack for container rules new ecs field (#3370) Isai 2024-01-05 18:42:42 -05:00
  • ba6cfc9d6b [Tuning] Update min_stack for container rules new ecs field (#3370) Isai 2024-01-05 18:42:42 -05:00
  • a0f82c3f12 [Tuning] Update min_stack for container rules new ecs field (#3370) Isai 2024-01-05 18:42:42 -05:00
  • d7cc37993d [New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241) Isai 2024-01-05 10:28:24 -05:00
  • 5e57d440ed [New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241) Isai 2024-01-05 10:28:24 -05:00
  • 10b241dcc5 [New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241) Isai 2024-01-05 10:28:24 -05:00
  • 4638fae505 [New Rule] Mount Launched Inside a Privileged Container (#3245) Isai 2024-01-05 10:17:55 -05:00
  • 187091ef23 [New Rule] Mount Launched Inside a Privileged Container (#3245) Isai 2024-01-05 10:17:55 -05:00
  • db5e1e5cf2 [New Rule] Mount Launched Inside a Privileged Container (#3245) Isai 2024-01-05 10:17:55 -05:00
  • ad85cd74a7 [New Rule] Potential Container Escape via Modified notify_on_release File (#3244) Isai 2024-01-04 22:14:39 -05:00
  • 4e3efa0cf0 [New Rule] Potential Container Escape via Modified notify_on_release File (#3244) Isai 2024-01-04 22:14:39 -05:00
  • 8e1dad0aeb [New Rule] Potential Container Escape via Modified notify_on_release File (#3244) Isai 2024-01-04 22:14:39 -05:00
  • 5b4a8172f6 [New Rule] Potential Container Escape via Modified release_agent File (#3242) Isai 2024-01-04 21:24:54 -05:00
  • 2ee626a77f [New Rule] Potential Container Escape via Modified release_agent File (#3242) Isai 2024-01-04 21:24:54 -05:00
  • 0a37df713b [New Rule] Potential Container Escape via Modified release_agent File (#3242) Isai 2024-01-04 21:24:54 -05:00
  • 667df1b714 [FR] Add --include-metadata argument to export-rules command (#3365) Terrance DeJesus 2024-01-04 16:02:48 -05:00
  • bb7bf106f7 [FR] Add --include-metadata argument to export-rules command (#3365) Terrance DeJesus 2024-01-04 16:02:48 -05:00
  • d7b62395e7 [FR] Add --include-metadata argument to export-rules command (#3365) Terrance DeJesus 2024-01-04 16:02:48 -05:00
  • 0ce0bab466 [Rule Tuning] Windows DR Tuning - 8 (#3353) Jonhnathan 2024-01-03 12:00:29 -03:00
  • bcef5d74e1 [Rule Tuning] Windows DR Tuning - 8 (#3353) Jonhnathan 2024-01-03 12:00:29 -03:00
  • 7b1215ccf1 [Rule Tuning] Windows DR Tuning - 8 (#3353) Jonhnathan 2024-01-03 12:00:29 -03:00
  • 0033527145 [New] Potential Evasion via Windows Filtering Platform (#3356) Samirbous 2024-01-03 12:50:12 +00:00
  • 3f8c0295d0 [New] Potential Evasion via Windows Filtering Platform (#3356) Samirbous 2024-01-03 12:50:12 +00:00
  • b7e21d8c29 [New] Potential Evasion via Windows Filtering Platform (#3356) Samirbous 2024-01-03 12:50:12 +00:00
  • b319d0e68b Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358) github-actions[bot] 2024-01-02 12:25:33 -05:00
  • f882c20919 Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358) integration-v8.10.9 github-actions[bot] 2024-01-02 12:25:33 -05:00
  • f37d13f29b Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358) github-actions[bot] 2024-01-02 12:25:33 -05:00
  • 5a96f4d51a Merge branch 'main' of github.com:elastic/detection-rules Mika Ayenson 2024-01-02 11:15:01 -06:00
  • 0acd802bd0 deprecating 'Malicious Remote File Creation' (#3342) Terrance DeJesus 2023-12-20 08:49:45 -05:00
  • 9c9d0459ba deprecating 'Malicious Remote File Creation' (#3342) Terrance DeJesus 2023-12-20 08:49:45 -05:00
  • 7e85854e7b deprecating 'Malicious Remote File Creation' (#3342) Terrance DeJesus 2023-12-20 08:49:45 -05:00
  • 87f8e053ba [Deprecate] Potential Process Herpaderping Attempt (#3336) Samirbous 2023-12-19 20:59:48 +00:00
  • f3377e1460 [Deprecate] Potential Process Herpaderping Attempt (#3336) Samirbous 2023-12-19 20:59:48 +00:00
  • 341499a2bc [Deprecate] Potential Process Herpaderping Attempt (#3336) Samirbous 2023-12-19 20:59:48 +00:00
  • d9652ad592 [Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348) Terrance DeJesus 2023-12-19 15:36:45 -05:00
  • 49d2a748d0 [Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348) Terrance DeJesus 2023-12-19 15:36:45 -05:00
  • eafec1d857 [Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348) Terrance DeJesus 2023-12-19 15:36:45 -05:00
  • 54a17aa537 [Rule Tuning] Linux BBR Tuning (#3347) Ruben Groenewoud 2023-12-19 20:17:53 +01:00
  • 3247e1565b [Rule Tuning] Linux BBR Tuning (#3347) Ruben Groenewoud 2023-12-19 20:17:53 +01:00
  • b32733601a [Rule Tuning] Linux BBR Tuning (#3347) Ruben Groenewoud 2023-12-19 20:17:53 +01:00
  • 4c5b7548a1 [Security Content] Add Windows Investigation Guides (#3257) Jonhnathan 2023-12-19 12:38:28 -03:00
  • 1f2ae31f67 [Security Content] Add Windows Investigation Guides (#3257) Jonhnathan 2023-12-19 12:38:28 -03:00
  • 578936d37a [Security Content] Add Windows Investigation Guides (#3257) Jonhnathan 2023-12-19 12:38:28 -03:00
  • 51c4e5b413 [Rule Tuning] Windows DR Tuning - 7 (#3344) Jonhnathan 2023-12-18 14:27:55 -03:00
  • a635222776 [Rule Tuning] Windows DR Tuning - 7 (#3344) Jonhnathan 2023-12-18 14:27:55 -03:00