250ad4a8eb
* [New] Diverse AWS Rules - AWS EC2 Role GetCallerIdentity from New Source AS Organization - AWS CloudTrail API Request with TruffleHog User Agent * Create discovery_new_terms_vpn_asn_discovery_api_calls.toml * ++ * Update discovery_new_terms_sts_getcalleridentity_ec2_role_new_source_as.toml * Update discovery_new_terms_vpn_asn_discovery_api_calls.toml * Delete initial_access_aws_cloudtrail_trufflehog_user_agent.toml * Update discovery_new_terms_vpn_asn_discovery_api_calls.toml * Apply suggestion from @terrancedejesus Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Apply suggestion from @terrancedejesus Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Apply suggestion from @terrancedejesus Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Revert "++" This reverts commit fbb69afa95f39d3bf83acf3aca601cc40fc98ea1. * Update discovery_new_terms_sts_getcalleridentity_ec2_role_new_source_as.toml * Update discovery_new_terms_sts_getcalleridentity_ec2_role_new_source_as.toml * Update discovery_new_terms_sts_getcalleridentity_ec2_role_new_source_as.toml * ++ * ++ * Update discovery_new_terms_vpn_asn_discovery_api_calls.toml * ++ * ++ * ++ * ++ * Update execution_ec2_stop_start_with_user_data_modification.toml * Update execution_ec2_stop_start_with_user_data_modification.toml * Update execution_aws_ssm_session_manager_child_process.toml * Update execution_aws_ssm_session_manager_child_process.toml * Update execution_aws_ssm_session_manager_child_process.toml * ++ * ++ * ++ * ++ * ++ * ++ * Update defense_evasion_kms_key_policy_put.toml * Rename defense_evasion_kms_key_policy_put.toml to privilege_escalation_kms_key_policy_put.toml * Update privilege_escalation_iam_customer_managed_policy_version_created_or_set_default.toml * Update discovery_new_terms_sts_getcalleridentity_ec2_role_new_source_as.toml * Delete rules/integrations/aws/discovery_new_terms_ec2_describe_instance_userdata_unusual_context.toml similar rule exist * Update discovery_new_terms_vpn_asn_discovery_api_calls.toml * Apply suggestion from @imays11 Co-authored-by: Isai <59296946+imays11@users.noreply.github.com> * Apply suggestion from @imays11 Co-authored-by: Isai <59296946+imays11@users.noreply.github.com> * Update persistence_new_terms_ec2_create_keypair_unusual_source_as.toml * Update privilege_escalation_kms_key_policy_put.toml * Update privilege_escalation_iam_customer_managed_policy_version_created_or_set_default.toml * Update persistence_new_terms_ec2_create_keypair_unusual_source_as.toml * Update execution_aws_ssm_session_manager_child_process.toml * Update rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_version_created_or_set_default.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Update rules/integrations/aws/execution_ec2_stop_start_with_user_data_modification.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Update privilege_escalation_iam_privilege_operations_via_lambda_execution_role.toml * Apply suggestion from @imays11 Co-authored-by: Isai <59296946+imays11@users.noreply.github.com> * Update execution_ec2_stop_start_with_user_data_modification.toml --------- Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
rules/
Rules within this folder are organized by solution or platform. The structure is flattened out, because nested file hierarchies are hard to navigate and find what you're looking for. Each directory contains several .toml files, and the primary ATT&CK tactic is included in the file name when it's relevant (i.e. windows/execution_via_compiled_html_file.toml)
| folder | description |
|---|---|
. |
Root directory where rules are stored |
apm/ |
Rules that use Application Performance Monitoring (APM) data sources |
cross-platform/ |
Rules that apply to multiple platforms, such as Windows and Linux |
integrations/ |
Rules organized by Fleet integration |
linux/ |
Rules for Linux or other Unix based operating systems |
macos/ |
Rules for macOS |
ml/ |
Rules that use machine learning jobs (ML) |
network/ |
Rules that use network data sources |
promotions/ |
Rules that promote external alerts into detection engine alerts |
windows/ |
Rules for the Microsoft Windows Operating System |
Integration specific rules are stored in the integrations/ directory:
| folder | integration |
|---|---|
aws/ |
Amazon Web Services (AWS) |
azure/ |
Microsoft Azure |
cyberarkpas/ |
Cyber Ark Privileged Access Security |
endpoint/ |
Elastic Endpoint Security |
gcp/ |
Google Cloud Platform (GCP) |
google_workspace/ |
Google Workspace (formerly GSuite) |
o365/ |
Microsoft Office |
okta/ |
Okta |