613 Commits

Author SHA1 Message Date
Ruben Groenewoud 703959ca4b [Rule IG Tuning] Suspicious Command Execution via Web Server (#6249)
(cherry picked from commit eeacbcf228)
2026-06-04 11:42:46 +00:00
shashank-elastic 1cfe4250e0 Add missing guides (#6224)
(cherry picked from commit 16e60dcc18)
2026-06-01 16:46:04 +00:00
Ruben Groenewoud 882bead728 [New/Tuning] Misc. Linux Web Server Rules (#6222)
Removed changes from:
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml

(selectively cherry picked from commit 94d6f5f86a)
2026-06-01 15:44:44 +00:00
shashank-elastic c7ac88a693 Monthly Manifest and Schema Updation and investigation guide additions (#6220)
Removed changes from:
- rules/cross-platform/command_and_control_uncommon_dns_request_via_bun_or_nodejs.toml

(selectively cherry picked from commit e7ea532043)
2026-06-01 13:59:53 +00:00
Ruben Groenewoud 363d8bd61b [Rule Tuning] Attempt to Clear Kernel Ring Buffer (#6221)
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>

(cherry picked from commit be34ba9e30)
2026-06-01 12:07:28 +00:00
Samirbous 604d379b42 [Tuning] Diverse Recently Created Rules (#6191)
* Update persistence_kubernetes_admission_webhook_created_or_modified.toml

* Update credential_access_kubernetes_and_cloud_credential_paths_via_process_args.toml

* Update credential_access_kubernetes_and_cloud_credential_paths_via_process_args.toml

* Update persistence_kubernetes_static_pod_manifest_path_process_execution.toml

* Update execution_aws_ssm_session_manager_child_process.toml

* Update execution_aws_ssm_session_manager_child_process.toml

* Update initial_access_assume_role_with_web_identity_kubernetes_sa_from_external_asn.toml

* Update execution_aws_ssm_session_manager_child_process.toml

(cherry picked from commit 3bc6247888)
2026-06-01 10:09:05 +00:00
Ruben Groenewoud 87e03614f8 [New Rule] Segfault from Sensitive Process Detected (#6209)
* [New Rule] Segfault from Sensitive Process Detected

* ++

* Update credential_access_segfault_from_sensitive_process.toml

(cherry picked from commit 7a342e602f)
2026-05-29 14:27:03 +00:00
litemars bdd3ea32f6 bug in command flag (#6203)
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit cdff27092a)
2026-05-28 16:20:56 +00:00
Ruben Groenewoud 9f86f6a30b [New/Tuning] Suspicious Instance Metadata Service (IMDS) API Activity (#6178)
* [New/Tuning] Suspicious Instance Metadata Service (IMDS) API Activity

* signature trusted usage

* Add IGs + timestamp override

* Update rules/cross-platform/credential_access_suspicious_instance_metadata_service_api_request.toml

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* Add PowerShell and CMD to suspicious process list

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit 8aec6b7ea4)
2026-05-27 10:01:54 +00:00
Ruben Groenewoud d412cd668e [New Rules] NX-Console Supply Chain Attack (#6173)
* [New Rules] NX-Console Supply Chain Attack

* ++

* ++

* Optimize KQL query

* Adding auditd manager integration tag

* Update command_and_control_uncommon_dns_request_via_bun_or_nodejs.toml

(cherry picked from commit 1af18caf66)
2026-05-21 12:43:00 +00:00
Ruben Groenewoud 4ad1c7b3c9 [Rule Tuning/New Rule] Suspicious SUID Binary Execution (#6162)
(cherry picked from commit b87d2f5893)
2026-05-18 12:59:48 +00:00
Samirbous b318a24add [New] Kubernetes Static Pod Manifest File Access (#6094)
* [New] Kubernetes Static Pod Manifest File Access

The kubelet watches this directory for static pod manifests, a newly dropped manifest can schedule privileged workloads, maintain persistence across kubelet restarts, or tamper with control plane components on affected nodes. Unexpected creations should be reviewed alongside process ancestry and cluster context.

* Update persistence_kubernetes_static_pod_manifest_path_process_execution.toml

* Update persistence_kubernetes_static_pod_manifest_path_process_execution.toml

* ++

* Update persistence_kubernetes_static_pod_manifest_file_creation.toml

* Update persistence_kubernetes_static_pod_manifest_path_process_execution.toml

* Delete rules/integrations/cloud_defend/persistence_kubernetes_static_pod_manifest_file_creation.toml

(cherry picked from commit 73b821198f)
2026-05-18 11:15:21 +00:00
Samirbous 30f51c0738 [Tuning] Diverse Rules (#6129)
* Update command_and_control_auditd_curl_wget_from_container.toml

* Update credential_access_kubernetes_secrets_list_cluster_and_sensitive_namespaces.toml

* Update discovery_kubectl_secrets_all_namespaces.toml

* Update discovery_kubectl_secrets_all_namespaces.toml

* Update credential_access_kubernetes_secret_read_by_node_or_pod_service_account.toml

* Update execution_aws_ssm_session_manager_child_process.toml

* Update credential_access_kubernetes_secret_read_by_node_or_pod_service_account.toml

* Update credential_access_kubernetes_secret_read_by_node_or_pod_service_account.toml

* Update discovery_kubernetes_multi_resource_setup_recon.toml

* Update discovery_kubernetes_multi_resource_setup_recon.toml

* Update credential_access_kubernetes_multiple_secret_retrieval_burst.toml

* Update discovery_kubernetes_multi_resource_setup_recon.toml

Removed changes from:
- rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml

(selectively cherry picked from commit 85f59d9d4e)
2026-05-18 09:45:37 +00:00
Ruben Groenewoud 8ff36143be ++ (#6136)
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit 6174036bd2)
2026-05-15 11:31:51 +00:00
Samirbous 93c80dd378 [New] Suspicious SUID Binary Execution (Auditd Sequence) (#6104)
* [New] Suspicious SUID Binary Execution (Auditd Sequence)

using EQL sequence, convert this existing rule https://github.com/elastic/detection-rules/blob/ebe2a089b8806989e77531adde70314958851648/rules/linux/privilege_escalation_suspicious_suid_binary_execution.toml#L24 (compatible with Elastic Defend only).

- Auditd process event lacks process.args_count and process.parent.args_count
- auditd process events lacks process.command_line (only process.arg)

Dropped severity to medium reflect FPs that may come from those event limitations. but the rule logc matches on same LPe exploit instances:

* Update rules/linux/privilege_escalation_suspicious_suid_binary_execution_auditd_sequence.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/linux/privilege_escalation_suspicious_suid_binary_execution_auditd_sequence.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/linux/privilege_escalation_suspicious_suid_binary_execution_auditd_sequence.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/linux/privilege_escalation_suspicious_suid_binary_execution_auditd_sequence.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit 932bcb2ea4)
2026-05-08 20:35:40 +00:00
Samirbous 554cb83859 [New/Tuning] Potential Privilege Escalation via unshare Followed by Root (#6105)
* [New/Tuning] Potential Privilege Escalation via unshare Followed by Root Process

Detects a short sequence where a non-root user performs unshare-related namespace activity (often associated with user namespace privilege escalation primitives) and then a root process is executed shortly after. This can indicate a successful local privilege escalation attempt or suspicious namespace manipulation.

* Update privilege_escalation_unshare_to_root_process_auditd_sequence.toml

* Update rules/linux/privilege_escalation_unshare_to_root_process_auditd_sequence.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update privilege_escalation_unshare_to_root_process_auditd_sequence.toml

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit af50447032)
2026-05-08 20:02:14 +00:00
Samirbous e4bd661dff [New] Container Runtime CLI Execution with Suspicious Arguments (#6009)
* [New] Container Runtime CLI Execution with Suspicious Arguments

Detects ctr, crictl, or nerdctl on Linux when invoked with arguments associated with container lifecycle abuse, image staging, task or snapshot access, privileged or host-namespace flags, bind mounts, or CRI namespace targeting—patterns common during post-compromise container administration and breakout attempts.

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Create execution_container_runtime_cli_suspicious_args.toml

* Apply suggestion from @terrancedejesus

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* Update execution_container_runtime_cli_suspicious_args.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_args.toml

* Update execution_container_runtime_cli_suspicious_args.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update execution_container_runtime_cli_suspicious_args.toml

* Update execution_container_runtime_cli_suspicious_arguments.toml

* Update rules/integrations/cloud_defend/execution_container_runtime_cli_suspicious_args.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit d3eb02d85e)
2026-05-05 21:52:32 +00:00
Samirbous 8b38f04021 [New] Kubernetes and Cloud Credential Path Access via Process Arguments (#6007)
* [New] Kubernetes and Cloud Credential Path Access via Process Arguments

Detects a process connecting to a container runtime Unix socket (containerd or Docker) that is not a known legitimate
runtime component. Direct access to the container runtime socket allows an attacker to create, exec into, or manipulate containers without going through the Kubernetes API server, bypassing RBAC, admission webhooks, pod security standards, and Kubernetes audit logging entirely :

* Update credential_access_kubernetes_and_cloud_credential_paths_via_process_args.toml

* Apply suggestion from @imays11

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit 87a88628ee)
2026-05-05 16:49:33 +00:00
yuriShafet 992a180064 Fixing path in execution_shell_via_java_revshell_linux.toml (#6079)
The double slash // means this exclusion path will never match a real process argument of /opt/tomcat/statistics/statistics.jar.

(cherry picked from commit 36e6f54e43)
2026-05-05 14:03:01 +00:00
litemars 7a96b9a6d7 [Rule Tuning] Credential access collection sensitive files (#5952)
* credential_access_collection_sensitive_files fine-tuning

* Update credential_access_collection_sensitive_files.toml

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit c744a6c6a1)
2026-05-05 10:50:33 +00:00
Samirbous be4280f055 [New] Potential Privilege Escalation in Container via Runc Init (#5964)
* [New] Potential Privilege Escalation in Container via Runc Init

Identifies audit events for `runc init` child processes where the effective user is root and the login user ID is not root.
This pattern can indicate privilege escalation or credential separation abuse inside container runtimes, where a process executes  with elevated effective privileges while retaining a non-root audit identity.

* Update privilege_escalation_container_runc_init_effective_root_auditd.toml

* Update privilege_escalation_container_runc_init_effective_root_auditd.toml

* Update privilege_escalation_container_runc_init_effective_root_auditd.toml

* Update privilege_escalation_container_runc_init_effective_root_auditd.toml

* Update privilege_escalation_container_runc_init_effective_root_auditd.toml

(cherry picked from commit 245956a8d6)
2026-05-04 21:32:52 +00:00
Samirbous 0a2a48b1f6 [New/Tuning] Direct Kubelet API Access rules (#5996)
* [New/Tuning] Direct Kubelet API Access rules

- tuned existing rule for D4C to bump-up severity to high (low FP and very susp behavior) + added 10255 port and wss url.
- duplicated same rule logic for auditd/endpoint compatibility for both 10250 port in args and kubeletctl exec.
- added a new one using network event vs process argument for more resilience.

* ++

* Update discovery_potential_direct_kubelet_access_via_process_args.toml

* Update and rename discovery_potential_direct_kubelet_access_via_process_args.toml to lateral_movement_direct_kubelet_access_via_process_args.toml

* Update rules/linux/lateral_movement_direct_kubelet_access_via_process_args.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/linux/discovery_potential_kubeletctl_execution.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update discovery_potential_kubeletctl_execution.toml

* Update lateral_movement_kubelet_api_connection_attempt_internal_ip.toml

* Apply suggestion from @Aegrah

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Apply suggestion from @Aegrah

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

Removed changes from:
- rules/integrations/cloud_defend/execution_kubeletctl_execution.toml
- rules/integrations/cloud_defend/execution_potential_direct_kubelet_access_via_process_args.toml

(selectively cherry picked from commit 83406d8ce1)
2026-05-04 21:20:06 +00:00
Samirbous 39ba02e010 [New] Sensitive Identity File Open by Suspicious Process via Auditd (#5982)
* [New] Sensitive Identity File Open by Suspicious Process via Auditd

Detects Auditd opened-file reads on sensitive root and cluster paths (Kubernetes token mounts, kubelet and admin kubeconfig, PKI material, shadow, root SSH keys, root cloud CLI and Docker config) when the process looks like common copy or scripting utilities or the binary runs from temp or run staging. User home paths are excluded so file watches
stay explicit and aligned with auditd:

* ++

* Update credential_access_auditd_sensitive_cloud_and_host_identity_file_open.toml

* Update credential_access_auditd_sensitive_cloud_and_host_identity_file_open.toml

* Update rules/linux/credential_access_auditd_sensitive_cloud_and_host_identity_file_open.toml

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* Apply suggestion from @imays11

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Apply suggestion from @Mikaayenson

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit bf49a90eb0)
2026-05-03 10:26:23 +00:00
Samirbous 6761562843 [New] Nsenter to PID 1 Namespace via Auditd/D4C (#5988)
* [New] Nsenter to PID 1 Namespace via Auditd

we have an existing rule https://github.com/elastic/detection-rules/blob/0f521a0848420844f3af383f1dee8481d41b2e5b/rules/linux/privilege_escalation_docker_escape_via_nsenter.toml#L15 (compatible only with Elastic Defend `process.entry_leader.entry_meta.type == "container"`).

This rule is compatible with the auditd integration and scoped to Init/systemd PID namespace commonly targeted for container escape.

* Create privilege_escalation_nsenter_execution_inside_container.toml

* Update privilege_escalation_auditd_nsenter_target_host_pid.toml

* Update privilege_escalation_auditd_nsenter_target_host_pid.toml

* Update privilege_escalation_auditd_nsenter_target_host_pid.toml

* Update privilege_escalation_auditd_nsenter_target_host_pid.toml

* Update rules/linux/privilege_escalation_auditd_nsenter_target_host_pid.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update privilege_escalation_nsenter_execution_inside_container.toml

* Update privilege_escalation_auditd_nsenter_target_host_pid.toml

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 838e926058)
2026-05-02 13:57:40 +00:00
Samirbous 8095de3ef0 [New/Tuning] Chroot Execution in Container Context on Linux (#5992)
* [New/Tuning] Chroot Execution in Container Context on Linux

New rule compatible with auditd and ED using process.title and process.entry_leader.entry_meta.type and tuned an existing one (bum-up severity to high).

* Update rules/linux/privilege_escalation_chroot_execution_container_context.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 80f3ed464c)
2026-05-02 12:46:49 +00:00
Samirbous 2c1cc7d42d [New] Curl or Wget Execution from Container Context (#5975)
* [New] Curl or Wget Execution from Container Context

detect execution of curl/wget from container runtime.

* Update command_and_control_auditd_curl_wget_from_container.toml

* Update command_and_control_auditd_curl_wget_from_container.toml

* Apply suggestion from @terrancedejesus

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit e0c6e715fb)
2026-05-02 10:09:58 +00:00
Samirbous d6a3c913be [New] Unusual Process Connection to Docker or Containerd Socket (#6005)
* [New] Unusual Process Connection to Docker or Containerd Socket

Detects a process connecting to a container runtime Unix socket (containerd or Docker) that is not a known legitimate runtime component. Direct access to the container runtime socket allows an attacker to create, exec into, or manipulate containers without going through the Kubernetes API server, bypassing RBAC, admission webhooks, pod security standards, and Kubernetes audit logging entirely.

* Update discovery_unusual_process_connection_to_container_runtime_socket.toml

(cherry picked from commit 40213fa041)
2026-05-02 09:06:57 +00:00
Ruben Groenewoud fbe864b706 [Rule Tuning] Fixes for Unsupported Fields (#6025)
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit efa3fe5911)
2026-05-01 23:02:38 +00:00
Samirbous c0aaa9fd33 [Tuning/New] Namespace Manipulation Using Unshare (#6024)
* Update privilege_escalation_unshare_namespace_manipulation.toml

* Create privilege_escalation_unshare_namespace_manip.toml

* Apply suggestion from @Aegrah

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update privilege_escalation_unshare_namespace_manip.toml

* Update privilege_escalation_unshare_namespace_manipulation.toml

* Update privilege_escalation_unshare_namespace_manipulation.toml

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit ba8fa3ef0f)
2026-05-01 14:31:25 +00:00
Mika Ayenson, PhD 0c61ff5c00 Revert "[Tuning] Namespace Manipulation Using Unshare (#5989)" (#6023)
This reverts commit 175e043adf.

(cherry picked from commit a1458f0fd0)
2026-05-01 13:25:55 +00:00
Samirbous e1450873f7 [Tuning] Namespace Manipulation Using Unshare (#5989)
* Update privilege_escalation_unshare_namespace_manipulation.toml

* Update privilege_escalation_unshare_namespace_manipulation.toml

(cherry picked from commit 175e043adf)
2026-05-01 10:18:51 +00:00
Samirbous 0efb5a7b9e [New/Tuning] Linux LPE via SUID Shell (#5980)
* [New] Kubernetes Pod Exec with Curl or Wget to HTTPS

Detects pod or attach `exec` API calls where the decoded request query implies curl or wget fetching an https URL (avoid noisy local http services).

* Create execution_kubernetes_pod_exec_potential_reverse_shell.toml

* Update execution_kubernetes_pod_exec_curl_wget_https.toml

* Update execution_kubernetes_pod_exec_potential_reverse_shell.toml

* ++

* ++

* Add auditd rule for root-effective shell -p outside system paths; extend SUID/SGID exploitation coverage.

Made-with: Cursor

* Revert "++"

This reverts commit eb5631d80e.

* Revert "++"

This reverts commit 2d2c34ca21.

* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_curl_wget_https.toml

* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_potential_reverse_shell.toml

* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml

* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml

* Update rules/linux/privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml

---------

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 6b3b84ca38)
2026-05-01 09:53:10 +00:00
Ruben Groenewoud d79f64a4ce [Rule Tuning] Privilege Escalation via SUID/SGID (#6017)
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit 8dc3fef270)
2026-05-01 08:10:34 +00:00
Samirbous fe12a19052 [New] Suspicious SUID Binary Execution (#6018)
* [New] Suspicious SUDI Binary Execution

Detects execution of common privilege elevation helpers (su, sudo, pkexec, passwd, chsh, newgrp) under the root effective user when the real user and parent user are not root, combined with minimal argument counts and suspicious parent context (interpreters, short shell -c invocations, or parents running from user-writable paths) :

* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update privilege_escalation_suspicious_sudi_binary_execution.toml

* Update privilege_escalation_suspicious_sudi_binary_execution.toml

* Rename privilege_escalation_suspicious_sudi_binary_execution.toml to privilege_escalation_suspicious_suid_binary_execution.toml

* Update privilege_escalation_suspicious_suid_binary_execution.toml

* Update privilege_escalation_suspicious_suid_binary_execution.toml

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit f0467c8bed)
2026-04-30 16:40:06 +00:00
Eric Forte c1e21d5f44 [New] Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket (#6015)
* initial draft rule too noisy atm

* Switch To Sequence Rule
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 3371938045)
2026-04-30 16:25:55 +00:00
Ruben Groenewoud e9c4692be5 [New Rules] False Negatives for New BPFDoor Variants (#5939)
* [New Rules] False Negatives for New BPFDoor Variants

* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml

* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml

* IG Additions

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>

(cherry picked from commit 4512ec1735)
2026-04-22 06:05:05 +00:00
Terrance DeJesus 7fde924213 [Rule Tuning] Change event.dataset to data_stream.dataset (#5943)
* [Rule Tuning] Change event.dataset to data_stream.dataset

* updating ESQL field names

Removed changes from:
- rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml
- rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/initial_access_elastic_defend_alert_genai_utility_descendant.toml
- rules/cross-platform/initial_access_elastic_defend_alert_package_manager_ancestor.toml
- rules/cross-platform/multiple_alerts_llm_compromised_user_triage.toml
- rules/cross-platform/multiple_elastic_defend_behavior_rules_same_host_prevalence.toml
- rules/integrations/aws/discovery_multiple_discovery_api_calls_via_cli.toml
- rules/integrations/aws/discovery_organization_discovery_by_rare_user.toml
- rules/integrations/aws/discovery_s3_rapid_bucket_posture_api_calls.toml
- rules/integrations/aws/initial_access_iam_session_token_used_from_multiple_addresses.toml
- rules/integrations/aws/persistence_aws_attempt_to_register_virtual_mfa_device.toml
- rules/integrations/aws/persistence_iam_api_calls_via_user_session_token.toml
- rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml
- rules/integrations/aws/privilege_escalation_iam_update_assume_role_policy.toml
- rules/integrations/azure/credential_access_entra_id_excessive_account_lockouts.toml
- rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
- rules/windows/defense_evasion_masquerading_as_svchost.toml

(selectively cherry picked from commit deab1c0161)
2026-04-10 16:29:29 +00:00
Ruben Groenewoud 30f5390096 [Rule Tuning] Potential snap-confine Privilege Escalation (#5889)
* [Rule Tuning] Potential snap-confine Privilege Escalation via CVE-2026-3888

* ++

(cherry picked from commit 778781cc13)
2026-04-02 09:22:39 +00:00
Mika Ayenson, PhD e228bd7951 [Rule Tuning] Add Supplemental Mitre Mappings (#5876)
---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>

Removed changes from:
- rules/cross-platform/command_and_control_kubectl_networking_modification.toml
- rules/cross-platform/defense_evasion_potential_kubectl_impersonation.toml
- rules/cross-platform/defense_evasion_potential_kubectl_masquerading.toml
- rules/cross-platform/discovery_kubectl_permission_discovery.toml
- rules/cross-platform/discovery_web_server_local_file_inclusion_activity.toml
- rules/cross-platform/discovery_web_server_remote_file_inclusion_activity.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml
- rules/cross-platform/initial_access_exfiltration_new_usb_device_mounted.toml
- rules/integrations/aws/initial_access_iam_session_token_used_from_multiple_addresses.toml
- rules/integrations/aws/persistence_aws_attempt_to_register_virtual_mfa_device.toml
- rules/integrations/aws/persistence_iam_api_calls_via_user_session_token.toml
- rules/integrations/aws/privilege_escalation_iam_customer_managed_policy_attached_to_role.toml
- rules/integrations/aws/privilege_escalation_iam_update_assume_role_policy.toml
- rules/integrations/azure/ml_azure_rare_method_by_city.toml
- rules/integrations/azure/ml_azure_rare_method_by_country.toml
- rules/integrations/azure/ml_azure_rare_method_by_user.toml
- rules/integrations/azure/persistence_entra_id_service_principal_federated_issuer_modified.toml
- rules/integrations/cloud_defend/command_and_control_curl_socks_proxy_detected_inside_container.toml
- rules/integrations/cloud_defend/command_and_control_interactive_file_download_from_internet.toml
- rules/integrations/cloud_defend/command_and_control_tunneling_and_port_forwarding.toml
- rules/integrations/cloud_defend/credential_access_cloud_creds_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_collection_sensitive_files_compression_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_sensitive_keys_or_passwords_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_service_account_token_or_cert_read.toml
- rules/integrations/cloud_defend/defense_evasion_decoded_payload_piped_to_interpreter.toml
- rules/integrations/cloud_defend/defense_evasion_file_creation_execution_deletion_cradle.toml
- rules/integrations/cloud_defend/defense_evasion_interactive_process_execution_from_suspicious_directory.toml
- rules/integrations/cloud_defend/defense_evasion_ld_preload_shared_object_modified_inside_a_container.toml
- rules/integrations/cloud_defend/defense_evasion_potential_evasion_via_encoded_payload.toml
- rules/integrations/cloud_defend/discovery_dns_enumeration.toml
- rules/integrations/cloud_defend/discovery_environment_enumeration.toml
- rules/integrations/cloud_defend/discovery_kubelet_certificate_file_access.toml
- rules/integrations/cloud_defend/discovery_kubelet_pod_discovery_via_builtin_utilities.toml
- rules/integrations/cloud_defend/discovery_privilege_boundary_enumeration_from_interactive_process.toml
- rules/integrations/cloud_defend/discovery_service_account_namespace_read.toml
- rules/integrations/cloud_defend/discovery_suspicious_network_tool_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_container_management_binary_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_direct_interactive_kubernetes_api_request.toml
- rules/integrations/cloud_defend/execution_interactive_file_creation_in_system_binary_locations.toml
- rules/integrations/cloud_defend/execution_kubeletctl_execution.toml
- rules/integrations/cloud_defend/execution_netcat_listener_established_inside_a_container.toml
- rules/integrations/cloud_defend/execution_payload_downloaded_and_piped_to_shell.toml
- rules/integrations/cloud_defend/execution_potential_direct_kubelet_access_via_process_args.toml
- rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml
- rules/integrations/cloud_defend/execution_suspicious_interactive_interpreter_command_execution.toml
- rules/integrations/cloud_defend/execution_tool_installation.toml
- rules/integrations/cloud_defend/persistence_modification_of_persistence_relevant_files.toml
- rules/integrations/cloud_defend/persistence_ssh_authorized_keys_modification_inside_a_container.toml
- rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml
- rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml
- rules/integrations/cloud_defend/privilege_escalation_potential_container_escape_via_modified_release_agent_file.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_city.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_country.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_user.toml
- rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml
- rules/linux/discovery_docker_socket_discovery.toml
- rules/linux/discovery_kubeconfig_file_discovery.toml
- rules/linux/execution_kubectl_apply_pod_from_url.toml
- rules/linux/lateral_movement_kubeconfig_file_activity.toml
- rules/linux/persistence_kubernetes_sensitive_file_activity.toml
- rules/windows/execution_windows_script_from_internet.toml
- rules_building_block/discovery_kubectl_workload_and_cluster_discovery.toml

(selectively cherry picked from commit 8993d1450b)
2026-04-01 14:14:12 +00:00
Ruben Groenewoud 593eee81fa [Rule Tuning] Python Path File (pth) Creation (#5880)
* [Rule Tuning] Python Path File (pth) Creation

* ++

* ++

* ++

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit befd78524e)
2026-03-26 15:58:37 +00:00
Samirbous a84cf9191f [Tuning] Expand compatibility to extra OS (#5883)
* Update and rename exfiltration_potential_curl_data_exfiltration.toml to exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update execution_kubernetes_direct_api_request_via_curl_or_wget.toml

* ++

* ++

* Update rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/cross-platform/exfiltration_potential_curl_data_exfiltration.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

Removed changes from:
- rules/linux/command_and_control_kubectl_networking_modification.toml
- rules/linux/defense_evasion_potential_kubectl_impersonation.toml
- rules/linux/defense_evasion_potential_kubectl_masquerading.toml
- rules/linux/discovery_kubectl_permission_discovery.toml
- rules/linux/execution_kubernetes_direct_api_request_via_curl_or_wget.toml

(selectively cherry picked from commit 5d5e1d9ca4)
2026-03-26 12:11:46 +00:00
shashank-elastic 9d0fc7a0da Add investigation guide for database dumping activity (#5871)
(cherry picked from commit 07ccecb94b)
2026-03-23 16:54:28 +00:00
Ruben Groenewoud a46b961aae [New Rules] AppArmor Exploitation (CrackArmor) (#5842)
* [New Rule] AppArmor Profile Compilation via apparmor_parser

* [New Rule] Suspicious Write Attempt to AppArmor Policy Management Files

* ++

* 2 more rules for Auditd

* ++

* Update defense_evasion_apparmor_profile_compilation.toml

* Apply suggestion from @Aegrah

* Update rules/linux/defense_evasion_apparmor_profile_compilation.toml

(cherry picked from commit 5216bf2d0c)
2026-03-23 08:39:21 +00:00
Ruben Groenewoud 6c1fa0d44e [New Rule] Potential snap-confine Privilege Escalation via CVE-2026-3888 (#5845)
* [New Rule] Potential snap-confine Privilege Escalation via CVE-2026-3888

* Added IG

* ++

* ++

* IG fix

(cherry picked from commit de6eb0f10d)
2026-03-20 08:35:50 +00:00
Ruben Groenewoud c8c1ee0e65 [New/Tuning] New DB Dump Rule & Tuning wget/curl DRs (#5832)
* [Rule Tuning] Tuning wget/curl DRs

* [New Rule] Potential Database Dumping Activity

* Update exfiltration_potential_curl_data_exfiltration.toml

* Expand URL patterns in curl data exfiltration rule

* Update rules/linux/exfiltration_potential_wget_data_exfiltration.toml

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* Simplify process name conditions for database dumping

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit a4b614c681)
2026-03-19 12:59:00 +00:00
Ruben Groenewoud f34a93a641 [Rule Tuning] Dynamic Linker Copy (#5841)
(cherry picked from commit 5d3e17eaff)
2026-03-17 16:15:59 +00:00
Ruben Groenewoud 6a39e7323d [Rule Tuning] Base64 Decoded Payload Piped to Interpreter (#5811)
(cherry picked from commit 99bdb22a8d)
2026-03-09 14:07:43 +00:00
Ruben Groenewoud bd76c6f854 [Rule Tuning] agent.id --> host.id new_terms Key Modification (#5802)
* [Rule Tuning] `agent.id` --> `host.id` Migration

* Updated_date bump

(cherry picked from commit aaf99b1873)
2026-03-02 12:26:04 +00:00
Eric Forte 2c0f9da33d [Rule Tuning] Telnet Authentication Bypass Rule Tuning (#5771)
* Add xinetd in process names

(cherry picked from commit 4201fe6f8a)
2026-02-25 20:44:54 +00:00
Ruben Groenewoud 199401ded3 [New Rules] Kernel Discovery & BPF Load/Tampering via bpftool (#5743)
* [New Rules] BPF Load & Tampering via bpftool

* Update persistence_bpf_program_or_map_load.toml

* [New Rule] Kernel Instrumentation Discovery via kprobes and tracefs

* Update defense_evasion_bpf_program_tampering.toml

* Update persistence_bpf_program_or_map_load.toml

* Enhance note with investigation and response details

Added detailed investigation guide and response steps for kernel instrumentation discovery via kprobes and tracefs.

(cherry picked from commit c349c8eca7)
2026-02-23 15:34:56 +00:00