95cf506c9d
* [New] Suricata and Elastic Defend - Command and Control Correlation This detection correlates Suricata alerts and events with Elastic Defend network events to identify the source process performing the network activity. * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * Update rules/cross-platform/command_and_control_suricata_elastic_defend_c2.toml * Update rules/cross-platform/command_and_control_suricata_elastic_defend_c2.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update command_and_control_suricata_elastic_defend_c2.toml * Update command_and_control_suricata_elastic_defend_c2.toml * add suricata to schemas * merge from main * reset schemas * Update rules/cross-platform/command_and_control_suricata_elastic_defend_c2.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> --------- Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> Co-authored-by: Mika Ayenson <Mika.ayenson@elastic.co> Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>