c619844b0d
* Support ecs field for IM rule * update time interval * Change additional lookback to 5 minutes * Add old rule * Add newline * Update rules/cross-platform/threat_intel_module_match.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Remove im legacy rule * Udpdate name and description * Remove min_stack_comment * Keep 2 IM rule * add min_stack_comments to rule * Update rules/cross-platform/threat_intel_indicator_match.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * adds new rules Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Ece Özalp <ozale272@newschool.edu> Co-authored-by: Ece Ozalp <ece.ozalp@elastic.co>