b39cfc34e6
* [New] First Time Seen Elastic Defend Behavior Alert This rule detects Elastic Defend behavior alerts that are observed for the first time today when compared against the previous 7 days of alert history. It highlights low-volume, newly observed alerts tied to a specific detection rule on a single agent, which may indicate early-stage malicious activity or initial execution of suspicious behavior : * Update first_time_seen_elastic_defend_alert.toml * ++ * Update first_time_seen_elastic_defend_alert.toml * ++ * Update fist_time_seen_elastic_detection_rule.toml * Update fist_time_seen_elastic_detection_rule.toml * Update rules/cross-platform/first_time_seen_elastic_defend_alert.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/fist_time_seen_elastic_detection_rule.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/fist_time_seen_elastic_detection_rule.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update fist_time_seen_elastic_detection_rule.toml * Update first_time_seen_elastic_defend_alert.toml * Update rules/cross-platform/first_time_seen_elastic_defend_alert.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/cross-platform/first_time_seen_elastic_defend_alert.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/cross-platform/fist_time_seen_elastic_detection_rule.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update first_time_seen_elastic_defend_alert.toml * Update and rename fist_time_seen_elastic_detection_rule.toml to newly_observed_elastic_detection_rule.toml * Rename first_time_seen_elastic_defend_alert.toml to newly_observed_elastic_defend_alert.toml * Update newly_observed_elastic_defend_alert.toml * Update newly_observed_elastic_detection_rule.toml * Update newly_observed_elastic_defend_alert.toml * Update newly_observed_elastic_detection_rule.toml * Update newly_observed_elastic_defend_alert.toml * Update newly_observed_elastic_detection_rule.toml * Update newly_observed_elastic_detection_rule.toml --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>