Ruben Groenewoud
1c1632e0b9
[Rule Tuning] Linux DR Tuning - 3 ( #5483 )
...
* [Rule Tuning] Linux DR Tuning - 3
* Update rules/linux/credential_access_aws_creds_search_inside_container.toml
* Adjust thresholds and expand event action handling
* Update credential_access_potential_linux_ssh_bruteforce_external.toml
* Increase threshold for SSH brute force detection
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update credential_access_ssh_backdoor_log.toml
Removed 'auditbeat-*' from the index list.
* Refactor credential access rule for clarity
Removed redundant event.action expansion and filtering logic.
* Refactor ESQL query for SSH brute force detection
Refactor ESQL query to improve readability and maintainability by moving the event.action expansion and filtering logic.
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update credential_access_potential_successful_linux_ftp_bruteforce.toml
* Update credential_access_potential_successful_linux_rdp_bruteforce.toml
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Add time window truncation to bruteforce rule
* Add time window truncation to SSH brute force rule
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update SSH brute force detection rule to EQL
* Update CIDR match conditions for SSH brute force rule
* Update EQL query for SSH brute force detection
2026-01-08 13:32:43 +01:00
..
2026-01-06 16:18:04 +01:00
2026-01-06 16:18:04 +01:00
2026-01-06 16:18:04 +01:00
2025-02-05 15:25:45 -03:00
2026-01-06 16:18:04 +01:00
2026-01-08 10:11:05 +01:00
2026-01-06 16:18:04 +01:00
2026-01-06 17:00:55 +01:00
2025-07-08 00:25:42 +05:30
2026-01-06 17:00:55 +01:00
2026-01-06 17:00:55 +01:00
2025-01-28 14:43:00 +01:00
2026-01-06 17:00:55 +01:00
2025-03-20 20:32:07 +05:30
2026-01-06 17:00:55 +01:00
2026-01-06 17:00:55 +01:00
2026-01-06 17:00:55 +01:00
2025-12-15 10:44:08 +01:00
2025-02-03 21:27:50 +05:30
2026-01-06 17:00:55 +01:00
2026-01-06 17:00:55 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2026-01-08 13:32:43 +01:00
2025-11-25 01:08:15 +05:30
2025-10-06 13:19:22 +02:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2025-11-25 01:08:15 +05:30
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2025-11-25 01:08:15 +05:30
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2025-12-15 10:25:36 +01:00
2026-01-08 10:45:32 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 10:45:32 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-03-20 20:32:07 +05:30
2025-03-20 20:32:07 +05:30
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-01-22 14:43:30 -06:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-11-10 16:11:16 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-02-05 15:25:45 -03:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-12-12 14:28:12 +00:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-12-08 22:07:46 +05:30
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2025-11-10 16:03:39 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 11:10:46 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2025-11-24 15:08:39 -05:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-08 10:01:11 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2025-01-22 11:17:38 -06:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2025-03-20 20:32:07 +05:30
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2025-03-20 20:32:07 +05:30
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-08 09:32:57 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-10-17 09:29:17 +02:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-04-10 14:26:40 +02:00
2026-01-07 16:31:13 +01:00
2025-11-10 16:03:39 +01:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2025-02-05 15:25:45 -03:00
2025-02-05 15:25:45 -03:00
2025-02-05 15:25:45 -03:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2025-03-20 20:32:07 +05:30
2025-01-22 11:17:38 -06:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-07-07 11:27:48 -04:00
2026-01-07 16:31:13 +01:00
2025-02-05 15:25:45 -03:00
2025-02-05 15:25:45 -03:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2026-01-07 16:31:13 +01:00
2025-11-10 16:03:39 +01:00