204f0b2ebc
* [Tuning] Adds host metadata to the setup requirements Rules requiring host.ip and that are compatible with Elastic Defend integration can be impacting by windows].advanced.set_extended_host_information if set to the default value (false), host.ip won't be populated from 8.18+ (only host.name and host.os and host.id). Related SDH https://github.com/elastic/sdh-endpoint/issues/722 * ++ * Update rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_process_args.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_session_duration.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_high_remote_file_size.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_high_variance_rdp_session_duration.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_rare_remote_file_directory.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_unusual_time_for_an_rdp_session.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_spike_in_connections_from_a_source_ip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_rare_remote_file_extension.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/integrations/lmd/lateral_movement_ml_spike_in_connections_to_a_destination_ip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update lateral_movement_ml_spike_in_rdp_processes.toml * Apply suggestion from @Mikaayenson Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>