937a7a35e6
* [New Rule] Azure Arc Kubernetes Cluster Connect Abuse Fixes #5823 * rename, adjusted query * adding KEEP * * adjusting maturity * added to non-ecs schema * updating rule * addressing unit test failures * adjustments to logic, mitre mappings, unit test failures, etc. * Update rules/integrations/azure/initial_access_azure_arc_cluster_credential_access_unusual_source.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>