2276987104
* [New] Elastic Defend Alert from GenAI Utility or Descendant Detects Elastic Defend alerts (behavior, malicious file, memory signature, shellcode) where the alerted process or its direct parent is a GenAI coding or assistant utility * Rename multiple_alerts_elastic_defend_genai_utility_descendant.toml to initial_access_elastic_defend_genai_utility_descendant.toml * Update initial_access_elastic_defend_genai_utility_descendant.toml * Rename initial_access_elastic_defend_genai_utility_descendant.toml to initial_access_elastic_defend_alert_genai_utility_descendant.toml * Update initial_access_elastic_defend_alert_genai_utility_descendant.toml * ++ * ++ * ++ * Update initial_access_elastic_defend_alert_genai_utility_descendant.toml * Update initial_access_elastic_defend_alert_genai_utility_descendant.toml * Update initial_access_elastic_defend_alert_genai_utility_descendant.toml * Update rules/cross-platform/initial_access_elastic_defend_alert_genai_utility_descendant.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Update rules/cross-platform/initial_access_elastic_defend_alert_genai_utility_descendant.toml Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com> --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>