-
e7fd90f2b1
[FR] Update Validate Integrations to Check Fields Across All Schema Variations (#3372)
Mika Ayenson
2024-01-18 15:42:22 -06:00
-
a873abbb5b
[FR] Update Validate Integrations to Check Fields Across All Schema Variations (#3372)
Mika Ayenson
2024-01-18 15:42:22 -06:00
-
8a2475b5e3
Linux Process Capabilities Enrichment Detection Rules (#3366)
shashank-elastic
2024-01-18 22:49:43 +05:30
-
1a2ef4b867
Linux Process Capabilities Enrichment Detection Rules (#3366)
shashank-elastic
2024-01-18 22:49:43 +05:30
-
7367f37584
[Rule Tuning] Update
timestamp_override Unit Tests and Fix Rules Missing Field (#3368)
Terrance DeJesus
2024-01-17 14:14:38 -05:00
-
869988c20f
[Rule Tuning] Update
timestamp_override Unit Tests and Fix Rules Missing Field (#3368)
Terrance DeJesus
2024-01-17 14:14:38 -05:00
-
1c10c37468
[Rule Tuning] Update
timestamp_override Unit Tests and Fix Rules Missing Field (#3368)
Terrance DeJesus
2024-01-17 14:14:38 -05:00
-
652acc0f07
[Rule Tuning] Windows DR Tuning - 12 (#3364)
Jonhnathan
2024-01-17 13:19:12 -03:00
-
11c929f019
[Rule Tuning] Windows DR Tuning - 12 (#3364)
Jonhnathan
2024-01-17 13:19:12 -03:00
-
f6ba12a700
[Rule Tuning] Windows DR Tuning - 12 (#3364)
Jonhnathan
2024-01-17 13:19:12 -03:00
-
5d9277280c
[Tuning] Add logs-system. index where applicable (#3390)
sbousseaden
2024-01-17 13:49:59 +00:00
-
c6725b5642
[Tuning] Add logs-system. index where applicable (#3390)
sbousseaden
2024-01-17 13:49:59 +00:00
-
27262a585b
[Tuning] Add logs-system. index where applicable (#3390)
sbousseaden
2024-01-17 13:49:59 +00:00
-
d73da3d1d5
[Rule Tuning] Windows DR Tuning - 13 (#3369)
Jonhnathan
2024-01-17 09:53:18 -03:00
-
91ee5caf94
[Rule Tuning] Windows DR Tuning - 13 (#3369)
Jonhnathan
2024-01-17 09:53:18 -03:00
-
71cec2a0e1
[Rule Tuning] Windows DR Tuning - 13 (#3369)
Jonhnathan
2024-01-17 09:53:18 -03:00
-
345298fe4f
[Rule Tuning] Windows DR Tuning - 10 (#3355)
Jonhnathan
2024-01-17 09:44:10 -03:00
-
b1c8876c53
[Rule Tuning] Windows DR Tuning - 10 (#3355)
Jonhnathan
2024-01-17 09:44:10 -03:00
-
c6ab294627
[Rule Tuning] Windows DR Tuning - 10 (#3355)
Jonhnathan
2024-01-17 09:44:10 -03:00
-
5601eadfc1
[New Rule] Network Connection via Sudo Binary (#3389)
Ruben Groenewoud
2024-01-17 09:47:58 +01:00
-
bf71869f01
[New Rule] Network Connection via Sudo Binary (#3389)
Ruben Groenewoud
2024-01-17 09:47:58 +01:00
-
4301dacfb8
[New Rule] Network Connection via Sudo Binary (#3389)
Ruben Groenewoud
2024-01-17 09:47:58 +01:00
-
e7c4eb743a
[New Rule] Kernel Driver Load by non-root User (#3378)
Ruben Groenewoud
2024-01-17 09:34:25 +01:00
-
ab977df20d
[New Rule] Kernel Driver Load by non-root User (#3378)
Ruben Groenewoud
2024-01-17 09:34:25 +01:00
-
a9285445cf
[New Rule] Kernel Driver Load by non-root User (#3378)
Ruben Groenewoud
2024-01-17 09:34:25 +01:00
-
15e3f1866e
[Rule Tuning] Windows DR Tuning - 14 (#3376)
Jonhnathan
2024-01-15 11:16:04 -03:00
-
753578f336
[Rule Tuning] Windows DR Tuning - 14 (#3376)
Jonhnathan
2024-01-15 11:16:04 -03:00
-
0469785793
[Rule Tuning] Windows DR Tuning - 14 (#3376)
Jonhnathan
2024-01-15 11:16:04 -03:00
-
d281983b99
[Rule Tuning] Windows DR Tuning - 11 (#3359)
Jonhnathan
2024-01-15 10:55:50 -03:00
-
336dba7d05
[Rule Tuning] Windows DR Tuning - 11 (#3359)
Jonhnathan
2024-01-15 10:55:50 -03:00
-
caf38fd1b1
[Rule Tuning] Windows DR Tuning - 11 (#3359)
Jonhnathan
2024-01-15 10:55:50 -03:00
-
8c2415c00b
Linux Rule Tuning (#3379)
shashank-elastic
2024-01-11 18:07:03 +05:30
-
3302d03900
Linux Rule Tuning (#3379)
shashank-elastic
2024-01-11 18:07:03 +05:30
-
24d5528ab0
Linux Rule Tuning (#3379)
shashank-elastic
2024-01-11 18:07:03 +05:30
-
968814ddbb
[FR] Update _event_sort to use datetime instead of time (#3375)
Eric Forte
2024-01-09 10:59:01 -05:00
-
0afe7715f0
[FR] Update _event_sort to use datetime instead of time (#3375)
Eric Forte
2024-01-09 10:59:01 -05:00
-
6170db6231
[FR] Update _event_sort to use datetime instead of time (#3375)
Eric Forte
2024-01-09 10:59:01 -05:00
-
2f8ce915ab
[Rule Tuning] Dynamic Linker Copy (#3349)
Ruben Groenewoud
2024-01-08 10:56:31 +01:00
-
19c6cbf075
[Rule Tuning] Dynamic Linker Copy (#3349)
Ruben Groenewoud
2024-01-08 10:56:31 +01:00
-
df86882036
[Rule Tuning] Dynamic Linker Copy (#3349)
Ruben Groenewoud
2024-01-08 10:56:31 +01:00
-
4e20602c4c
[Rule Tuning] Linux cross-platform DRs (#3346)
Ruben Groenewoud
2024-01-08 10:44:03 +01:00
-
14faea2175
[Rule Tuning] Linux cross-platform DRs (#3346)
Ruben Groenewoud
2024-01-08 10:44:03 +01:00
-
788e2b2823
[Rule Tuning] Linux cross-platform DRs (#3346)
Ruben Groenewoud
2024-01-08 10:44:03 +01:00
-
f3273f1dac
[Rule Tuning] Linux DR Tuning - Part 3 (#3322)
Ruben Groenewoud
2024-01-08 10:16:44 +01:00
-
e95745664f
[Rule Tuning] Linux DR Tuning - Part 3 (#3322)
Ruben Groenewoud
2024-01-08 10:16:44 +01:00
-
6c91c1597d
[Rule Tuning] Linux DR Tuning - Part 3 (#3322)
Ruben Groenewoud
2024-01-08 10:16:44 +01:00
-
78618a1191
[Rule Tuning] Linux DR Tuning - Part 2 (#3321)
Ruben Groenewoud
2024-01-08 10:07:38 +01:00
-
629e4475f1
[Rule Tuning] Linux DR Tuning - Part 2 (#3321)
Ruben Groenewoud
2024-01-08 10:07:38 +01:00
-
36226e5428
[Rule Tuning] Linux DR Tuning - Part 2 (#3321)
Ruben Groenewoud
2024-01-08 10:07:38 +01:00
-
9017653e37
[Rule Tuning] Linux DR Tuning - Part 1 (#3316)
Ruben Groenewoud
2024-01-08 09:50:15 +01:00
-
db58d0c5f2
[Rule Tuning] Linux DR Tuning - Part 1 (#3316)
Ruben Groenewoud
2024-01-08 09:50:15 +01:00
-
b533642272
[Rule Tuning] Linux DR Tuning - Part 1 (#3316)
Ruben Groenewoud
2024-01-08 09:50:15 +01:00
-
e22cc8030e
[Rule Tuning] Windows DR Tuning - 9 (#3354)
Jonhnathan
2024-01-07 09:49:33 -03:00
-
d435ab7c44
[Rule Tuning] Windows DR Tuning - 9 (#3354)
Jonhnathan
2024-01-07 09:49:33 -03:00
-
724e34ba95
[Rule Tuning] Windows DR Tuning - 9 (#3354)
Jonhnathan
2024-01-07 09:49:33 -03:00
-
92ed682a51
[Tuning] Update min_stack for container rules new ecs field (#3370)
Isai
2024-01-05 18:42:42 -05:00
-
ba6cfc9d6b
[Tuning] Update min_stack for container rules new ecs field (#3370)
Isai
2024-01-05 18:42:42 -05:00
-
a0f82c3f12
[Tuning] Update min_stack for container rules new ecs field (#3370)
Isai
2024-01-05 18:42:42 -05:00
-
d7cc37993d
[New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241)
Isai
2024-01-05 10:28:24 -05:00
-
5e57d440ed
[New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241)
Isai
2024-01-05 10:28:24 -05:00
-
10b241dcc5
[New Rule] File System Debugger ‘debugfs’ Launched Inside a Privileged Container (#3241)
Isai
2024-01-05 10:28:24 -05:00
-
4638fae505
[New Rule] Mount Launched Inside a Privileged Container (#3245)
Isai
2024-01-05 10:17:55 -05:00
-
187091ef23
[New Rule] Mount Launched Inside a Privileged Container (#3245)
Isai
2024-01-05 10:17:55 -05:00
-
db5e1e5cf2
[New Rule] Mount Launched Inside a Privileged Container (#3245)
Isai
2024-01-05 10:17:55 -05:00
-
ad85cd74a7
[New Rule] Potential Container Escape via Modified notify_on_release File (#3244)
Isai
2024-01-04 22:14:39 -05:00
-
4e3efa0cf0
[New Rule] Potential Container Escape via Modified notify_on_release File (#3244)
Isai
2024-01-04 22:14:39 -05:00
-
8e1dad0aeb
[New Rule] Potential Container Escape via Modified notify_on_release File (#3244)
Isai
2024-01-04 22:14:39 -05:00
-
5b4a8172f6
[New Rule] Potential Container Escape via Modified release_agent File (#3242)
Isai
2024-01-04 21:24:54 -05:00
-
2ee626a77f
[New Rule] Potential Container Escape via Modified release_agent File (#3242)
Isai
2024-01-04 21:24:54 -05:00
-
0a37df713b
[New Rule] Potential Container Escape via Modified release_agent File (#3242)
Isai
2024-01-04 21:24:54 -05:00
-
667df1b714
[FR] Add
--include-metadata argument to export-rules command (#3365)
Terrance DeJesus
2024-01-04 16:02:48 -05:00
-
bb7bf106f7
[FR] Add
--include-metadata argument to export-rules command (#3365)
Terrance DeJesus
2024-01-04 16:02:48 -05:00
-
d7b62395e7
[FR] Add
--include-metadata argument to export-rules command (#3365)
Terrance DeJesus
2024-01-04 16:02:48 -05:00
-
0ce0bab466
[Rule Tuning] Windows DR Tuning - 8 (#3353)
Jonhnathan
2024-01-03 12:00:29 -03:00
-
bcef5d74e1
[Rule Tuning] Windows DR Tuning - 8 (#3353)
Jonhnathan
2024-01-03 12:00:29 -03:00
-
7b1215ccf1
[Rule Tuning] Windows DR Tuning - 8 (#3353)
Jonhnathan
2024-01-03 12:00:29 -03:00
-
0033527145
[New] Potential Evasion via Windows Filtering Platform (#3356)
Samirbous
2024-01-03 12:50:12 +00:00
-
3f8c0295d0
[New] Potential Evasion via Windows Filtering Platform (#3356)
Samirbous
2024-01-03 12:50:12 +00:00
-
b7e21d8c29
[New] Potential Evasion via Windows Filtering Platform (#3356)
Samirbous
2024-01-03 12:50:12 +00:00
-
b319d0e68b
Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358)
github-actions[bot]
2024-01-02 12:25:33 -05:00
-
f882c20919
Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358)
integration-v8.10.9
github-actions[bot]
2024-01-02 12:25:33 -05:00
-
f37d13f29b
Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (#3358)
github-actions[bot]
2024-01-02 12:25:33 -05:00
-
5a96f4d51a
Merge branch 'main' of github.com:elastic/detection-rules
Mika Ayenson
2024-01-02 11:15:01 -06:00
-
-
0acd802bd0
deprecating 'Malicious Remote File Creation' (#3342)
Terrance DeJesus
2023-12-20 08:49:45 -05:00
-
9c9d0459ba
deprecating 'Malicious Remote File Creation' (#3342)
Terrance DeJesus
2023-12-20 08:49:45 -05:00
-
7e85854e7b
deprecating 'Malicious Remote File Creation' (#3342)
Terrance DeJesus
2023-12-20 08:49:45 -05:00
-
87f8e053ba
[Deprecate] Potential Process Herpaderping Attempt (#3336)
Samirbous
2023-12-19 20:59:48 +00:00
-
f3377e1460
[Deprecate] Potential Process Herpaderping Attempt (#3336)
Samirbous
2023-12-19 20:59:48 +00:00
-
341499a2bc
[Deprecate] Potential Process Herpaderping Attempt (#3336)
Samirbous
2023-12-19 20:59:48 +00:00
-
d9652ad592
[Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348)
Terrance DeJesus
2023-12-19 15:36:45 -05:00
-
49d2a748d0
[Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348)
Terrance DeJesus
2023-12-19 15:36:45 -05:00
-
eafec1d857
[Bug] Fix BBR Folder Location Requirements for Specific Integrations (#3348)
Terrance DeJesus
2023-12-19 15:36:45 -05:00
-
54a17aa537
[Rule Tuning] Linux BBR Tuning (#3347)
Ruben Groenewoud
2023-12-19 20:17:53 +01:00
-
3247e1565b
[Rule Tuning] Linux BBR Tuning (#3347)
Ruben Groenewoud
2023-12-19 20:17:53 +01:00
-
b32733601a
[Rule Tuning] Linux BBR Tuning (#3347)
Ruben Groenewoud
2023-12-19 20:17:53 +01:00
-
4c5b7548a1
[Security Content] Add Windows Investigation Guides (#3257)
Jonhnathan
2023-12-19 12:38:28 -03:00
-
1f2ae31f67
[Security Content] Add Windows Investigation Guides (#3257)
Jonhnathan
2023-12-19 12:38:28 -03:00
-
578936d37a
[Security Content] Add Windows Investigation Guides (#3257)
Jonhnathan
2023-12-19 12:38:28 -03:00
-
51c4e5b413
[Rule Tuning] Windows DR Tuning - 7 (#3344)
Jonhnathan
2023-12-18 14:27:55 -03:00
-
a635222776
[Rule Tuning] Windows DR Tuning - 7 (#3344)
Jonhnathan
2023-12-18 14:27:55 -03:00