Eric Forte
27e0333d62
Field not supported in integration ( #6131 )
...
(cherry picked from commit d03b8d28b0 )
2026-05-13 12:22:01 +00:00
Terrance DeJesus
66ada45613
8.19 manual commit/push. Ref: https://github.com/elastic/detection-rules/issues/5940
2026-04-10 12:56:10 -04:00
Terrance DeJesus
7fde924213
[Rule Tuning] Change event.dataset to data_stream.dataset ( #5943 )
...
* [Rule Tuning] Change event.dataset to data_stream.dataset
* updating ESQL field names
Removed changes from:
- rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml
- rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/initial_access_elastic_defend_alert_genai_utility_descendant.toml
- rules/cross-platform/initial_access_elastic_defend_alert_package_manager_ancestor.toml
- rules/cross-platform/multiple_alerts_llm_compromised_user_triage.toml
- rules/cross-platform/multiple_elastic_defend_behavior_rules_same_host_prevalence.toml
- rules/integrations/aws/discovery_multiple_discovery_api_calls_via_cli.toml
- rules/integrations/aws/discovery_organization_discovery_by_rare_user.toml
- rules/integrations/aws/discovery_s3_rapid_bucket_posture_api_calls.toml
- rules/integrations/aws/initial_access_iam_session_token_used_from_multiple_addresses.toml
- rules/integrations/aws/persistence_aws_attempt_to_register_virtual_mfa_device.toml
- rules/integrations/aws/persistence_iam_api_calls_via_user_session_token.toml
- rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml
- rules/integrations/aws/privilege_escalation_iam_update_assume_role_policy.toml
- rules/integrations/azure/credential_access_entra_id_excessive_account_lockouts.toml
- rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
- rules/windows/defense_evasion_masquerading_as_svchost.toml
(selectively cherry picked from commit deab1c0161 )
2026-04-10 16:29:29 +00:00
Mika Ayenson, PhD
e228bd7951
[Rule Tuning] Add Supplemental Mitre Mappings ( #5876 )
...
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co >
Removed changes from:
- rules/cross-platform/command_and_control_kubectl_networking_modification.toml
- rules/cross-platform/defense_evasion_potential_kubectl_impersonation.toml
- rules/cross-platform/defense_evasion_potential_kubectl_masquerading.toml
- rules/cross-platform/discovery_kubectl_permission_discovery.toml
- rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml
- rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml
- rules/cross-platform/initial_access_exfiltration_new_usb_device_mounted.toml
- rules/integrations/aws/initial_access_iam_session_token_used_from_multiple_addresses.toml
- rules/integrations/aws/persistence_aws_attempt_to_register_virtual_mfa_device.toml
- rules/integrations/aws/persistence_iam_api_calls_via_user_session_token.toml
- rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml
- rules/integrations/aws/privilege_escalation_iam_update_assume_role_policy.toml
- rules/integrations/azure/ml_azure_rare_method_by_city.toml
- rules/integrations/azure/ml_azure_rare_method_by_country.toml
- rules/integrations/azure/ml_azure_rare_method_by_user.toml
- rules/integrations/azure/persistence_entra_id_service_principal_federated_issuer_modified.toml
- rules/integrations/cloud_defend/command_and_control_curl_socks_proxy_detected_inside_container.toml
- rules/integrations/cloud_defend/command_and_control_interactive_file_download_from_internet.toml
- rules/integrations/cloud_defend/command_and_control_tunneling_and_port_forwarding.toml
- rules/integrations/cloud_defend/credential_access_cloud_creds_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_collection_sensitive_files_compression_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_sensitive_keys_or_passwords_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_service_account_token_or_cert_read.toml
- rules/integrations/cloud_defend/defense_evasion_decoded_payload_piped_to_interpreter.toml
- rules/integrations/cloud_defend/defense_evasion_file_creation_execution_deletion_cradle.toml
- rules/integrations/cloud_defend/defense_evasion_interactive_process_execution_from_suspicious_directory.toml
- rules/integrations/cloud_defend/defense_evasion_ld_preload_shared_object_modified_inside_a_container.toml
- rules/integrations/cloud_defend/defense_evasion_potential_evasion_via_encoded_payload.toml
- rules/integrations/cloud_defend/discovery_dns_enumeration.toml
- rules/integrations/cloud_defend/discovery_environment_enumeration.toml
- rules/integrations/cloud_defend/discovery_kubelet_certificate_file_access.toml
- rules/integrations/cloud_defend/discovery_kubelet_pod_discovery_via_builtin_utilities.toml
- rules/integrations/cloud_defend/discovery_privilege_boundary_enumeration_from_interactive_process.toml
- rules/integrations/cloud_defend/discovery_service_account_namespace_read.toml
- rules/integrations/cloud_defend/discovery_suspicious_network_tool_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_container_management_binary_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_direct_interactive_kubernetes_api_request.toml
- rules/integrations/cloud_defend/execution_interactive_file_creation_in_system_binary_locations.toml
- rules/integrations/cloud_defend/execution_kubeletctl_execution.toml
- rules/integrations/cloud_defend/execution_netcat_listener_established_inside_a_container.toml
- rules/integrations/cloud_defend/execution_payload_downloaded_and_piped_to_shell.toml
- rules/integrations/cloud_defend/execution_potential_direct_kubelet_access_via_process_args.toml
- rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml
- rules/integrations/cloud_defend/execution_suspicious_interactive_interpreter_command_execution.toml
- rules/integrations/cloud_defend/execution_tool_installation.toml
- rules/integrations/cloud_defend/persistence_modification_of_persistence_relevant_files.toml
- rules/integrations/cloud_defend/persistence_ssh_authorized_keys_modification_inside_a_container.toml
- rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml
- rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml
- rules/integrations/cloud_defend/privilege_escalation_potential_container_escape_via_modified_release_agent_file.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_city.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_country.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_user.toml
- rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
- rules/linux/discovery_docker_socket_discovery.toml
- rules/linux/discovery_kubeconfig_file_discovery.toml
- rules/linux/execution_kubectl_apply_pod_from_url.toml
- rules/linux/lateral_movement_kubeconfig_file_activity.toml
- rules/linux/persistence_kubernetes_sensitive_file_activity.toml
- rules/windows/execution_windows_script_from_internet.toml
- rules_building_block/discovery_kubectl_workload_and_cluster_discovery.toml
(selectively cherry picked from commit 8993d1450b )
2026-04-01 14:14:12 +00:00
Ruben Groenewoud
579f9fb921
[Rule Tuning] Dormant & Deprecated Rule Clean-Up ( #5672 )
...
* Updated kubernetes.audit.requestObject.spec.containers.image type of text to Keyword
* [Rule Tuning] Dormant & Deprecated Rule Clean-Up
* [Rule Tuning] Dormant & Deprecated Rule Clean-Up
* Few more deprecations
* ++
* Update unit test syntax fix
* Update bad bytes
* ++
(cherry picked from commit 3cba3d7982 )
2026-02-05 12:25:47 +00:00
shashank-elastic
349d228ef0
Prep for Release 9.3 ( #5548 )
...
Removed changes from:
- detection_rules/etc/packages.yaml
- rules/integrations/azure/credential_access_entra_id_excessive_account_lockouts.toml
- rules/windows/execution_windows_script_from_internet.toml
(selectively cherry picked from commit 1ce072a4e5 )
2026-01-12 15:38:59 +00:00
Ruben Groenewoud
d1335dd374
[New Rules] Several GitHub Related Rules ( #5470 )
...
* [New Rules] Several GitHub Related Rules
* Added additional references
* Update defense_evasion_secret_scanning_disabled.toml
* Update persistence_new_pat_created.toml
* Added two more rules
* ++
* Update rules/integrations/github/impact_github_repository_activity_from_unusual_ip.toml
* Added github.repository_public to non_ecs
* Update impact_github_repository_activity_from_unusual_ip.toml
* Update rules/integrations/github/impact_high_number_of_failed_protected_branch_force_pushes_by_user.toml
* ++
* Update rules/integrations/github/exfiltration_high_number_of_cloning_by_user.toml
* Update rules/integrations/github/impact_high_number_of_closed_pull_requests_by_user.toml
* Update rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
* ++
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 34daf12d51 )
2026-01-08 16:20:38 +00:00
Terrance DeJesus
b12f1b3f09
[New Rule] GitHub Actions Bot Pushed to Repository for First Time ( #5438 )
...
* [New Rule] GitHub Actions Bot Pushed to Repository for First Time
Fixes #5437
* Update rules/integrations/github/initial_access_github_actions_bot_first_push_to_repo.toml
* Update rules/integrations/github/initial_access_github_actions_bot_first_push_to_repo.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/integrations/github/initial_access_github_actions_bot_first_push_to_repo.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Adjusted rule name
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit 57f18a1dcf )
2025-12-18 15:00:30 +00:00
Terrance DeJesus
daab50863a
[New Rule] GitHub Actions Workflow Injection Blocked ( #5433 )
...
* [New Rule] GitHub Actions Workflow Injection Blocked
Fixes #5431
* adjusts MITRE ATT&CK mappings
* adjusting file name
* updating GitHub integration schema; fixed MITRE mappings
* revert manifests / schemas to main
* added dynamic github fields to non-ecs file
* Update rules/integrations/github/initial_access_github_actions_workflow_injection_blocked.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Update rules/integrations/github/initial_access_github_actions_workflow_injection_blocked.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/integrations/github/initial_access_github_actions_workflow_injection_blocked.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* changed github actor ID reference
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit f43bf99698 )
2025-12-17 19:31:06 +00:00
Terrance DeJesus
b6e68831b9
[Rule Tuning] New GitHub Self Hosted Action Runner ( #5436 )
...
Fixes #5435
(cherry picked from commit f4085ad873 )
2025-12-10 15:57:17 +00:00
Samirbous
bded164d18
[New/Tuning] NPM Shai-Hulud coverage ( #5368 )
...
* [New/Tuning] NPM Shai-Hulud coverage
https://socket.dev/blog/shai-hulud-strikes-again-v2
* Update command_and_control_curl_wget_spawn_via_nodejs_parent.toml
* Update command_and_control_curl_wget_spawn_via_nodejs_parent.toml
* Update command_and_control_curl_wget_spawn_via_nodejs_parent.toml
* Update credential_access_trufflehog_execution.toml
* Update credential_access_trufflehog_execution.toml
* Update credential_access_trufflehog_execution.toml
* Update rules/cross-platform/command_and_control_curl_wget_spawn_via_nodejs_parent.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/command_and_control_curl_wget_spawn_via_nodejs_parent.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/command_and_control_curl_wget_spawn_via_nodejs_parent.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/execution_register_github_actions_runner.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/execution_via_github_actions_runner.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Create initial_access_github_register_self_hosted_runner.toml
* Update initial_access_github_register_self_hosted_runner.toml
* Update initial_access_github_register_self_hosted_runner.toml
* Update initial_access_github_register_self_hosted_runner.toml
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit 02979fec68 )
2025-12-02 10:58:37 +00:00
shashank-elastic
a1dd22efbe
Prep for Release 9.0 ( #4550 )
...
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit 059d7efa25 )
2025-03-20 15:07:35 +00:00
Mika Ayenson
fe8c81d762
[FR] Generate investigation guides ( #4358 )
2025-01-22 11:17:38 -06:00
Terrance DeJesus
052672b09f
[Rule Tuning] Update Okta and Github Min-Stack Versions for Release ( #4290 )
2024-12-09 20:58:33 +05:30
shashank-elastic
2c848c5111
Prep for Release 8.18 ( #4288 )
2024-12-09 18:25:13 +05:30
shashank-elastic
53cfeb76e3
Add event dataset for missing rule in Github integration ( #4278 )
2024-12-03 20:32:55 +05:30
shashank-elastic
5ab7565923
Minstack versions for Okta and Github Integration ( #4273 )
2024-11-27 18:39:41 +05:30
shashank-elastic
63e91c2f12
Back-porting Version Trimming ( #3704 )
2024-05-23 00:45:10 +05:30
Mika Ayenson
2c3dbfc039
Revert "Back-porting Version Trimming ( #3681 )"
...
This reverts commit 71d2c59b5c .
2024-05-22 13:51:46 -05:00
shashank-elastic
71d2c59b5c
Back-porting Version Trimming ( #3681 )
2024-05-23 00:11:50 +05:30
Isai
442435830f
[New Rules] UEBA GItHub BBRs and Rules ( #3174 )
...
* [New Rules] UEBA GItHub BBRs and Rules
A new set of BBRs and rules that will be used to trigger new UEBA GitHub threshold Rules.
* Update rules/integrations/github/impact_github_member_removed_from_organization.toml
* Apply suggestions from code review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* edited BBR rules
-removed newly added member rule
* updated integration manifests and schemas
* Updated min_stack for some rules based on newest GitHub integration schema manifest
* testing min_stack bump to 8.8 for new fields
* removing offending rule to troubleshoot seperately
* added UEBA tags and created UEBA threshold rule
* updated non-ecs-schema to add signal.rule.tags
* updated non-ecs-schema with kibana.alert.workflow_status
* updated rule.threat.tactic
* added user.name to non-ecs-schema
* added quotes to kibana.alert.workflow_status value
* removed trailing space from rule name
* update tags and optimize query for UEBA threshold rule
* removed integration field from Higher-Order rule
* Apply suggestions from code review
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
* adjusted new_terms order and rule types based on review feedback
* Apply suggestions from code review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* remove user.name from detection_rules/etc/non-ecs-schema.json
* fix json formatting
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2024-01-22 12:48:31 -05:00
Isai
374c9c6257
[New Rule] New GitHub App Installed ( #3055 )
...
* new rule
* Update rules/integrations/github/execution_new_github_app_installed.toml
* Update rules/integrations/github/execution_new_github_app_installed.toml
edits from review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* change query from event.module to event.dataset
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2023-10-12 20:10:20 -04:00
Isai
ef8f5620e1
[New Rule] New GitHub Owner Added ( #3090 )
...
* [New Rule] New GitHub Owner Added
new rule
* name change
* Apply suggestions from code review
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
---------
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
2023-10-06 15:57:26 -04:00
Isai
9593412847
[New Rule] GitHub Owner Role Granted to User ( #3087 )
...
* [New Rule] GitHub Owner Role Granted to User
new rule
* Update persistence_organization_owner_role_granted.toml
* updated integration schema
* changed timestamp_override
* Apply suggestions from code review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
2023-10-06 15:44:04 -04:00
Isai
9146e0965d
[New Rule] Github Repository Deleted ( #3056 )
...
* new rule
* Update rules/integrations/github/impact_github_repository_deleted.toml
* Update rules/integrations/github/impact_github_repository_deleted.toml
updates based on review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
2023-09-14 18:00:25 -04:00
Isai
904e37b732
[New Rule] GitHub Protected Branch Settings Changed ( #3054 )
...
* new rule file
* testing query change
* query changed back
* Update rules/integrations/github/defense_evasion_github_protected_branch_settings_changed.toml
updates based on review
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* updated integration manifests with github schema
* Update defense_evasion_github_protected_branch_settings_changed.toml
added event.dataset to query
* added timestamp_override
* changed timestamp_override to @timestamp
* changed timestamp_override
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
2023-09-14 17:16:51 -04:00