Commit Graph

3568 Commits

Author SHA1 Message Date
Mika Ayenson, PhD 024dfd6a27 [Bug ]Fix Kibana version parsing for package version (#5962)
* [Bug ]Fix kibana version parsing for package version

---------

Co-authored-by: Shashank K S <Shashank.Suryanarayana@elastic.co>

(cherry picked from commit 876e4ed535)
2026-04-22 15:29:10 +00:00
Terrance DeJesus 4a695f8850 [Rule Tuning] Multiple Device Token Hashes for Single Okta Session (#5948)
Fixes #5947

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>

(cherry picked from commit aa89d2512f)
2026-04-22 12:20:53 +00:00
Susan e7efeeb64f Add Entity related integrations ML rules with _ea job IDs and min_stack_version 9.4.0 (#5909)
Co-authored-by: Shashank K S <Shashank.Suryanarayana@elastic.co>

Removed changes from:
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_geo_country_iso_code.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_ip.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_port.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_region_name.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_written_to_external_device.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_written_to_external_device_airdrop.toml
- rules/integrations/ded/exfiltration_ml_rare_process_writing_to_external_device.toml
- rules/integrations/dga/command_and_control_ml_dga_high_sum_probability.toml
- rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_process_args.toml
- rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_session_duration.toml
- rules/integrations/lmd/lateral_movement_ml_high_remote_file_size.toml
- rules/integrations/lmd/lateral_movement_ml_high_variance_rdp_session_duration.toml
- rules/integrations/lmd/lateral_movement_ml_rare_remote_file_directory.toml
- rules/integrations/lmd/lateral_movement_ml_rare_remote_file_extension.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_connections_from_a_source_ip.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_connections_to_a_destination_ip.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_rdp_processes.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_remote_file_transfers.toml
- rules/integrations/lmd/lateral_movement_ml_unusual_time_for_an_rdp_session.toml
- rules/integrations/pad/privileged_access_ml_linux_high_count_privileged_process_events_by_user.toml
- rules/integrations/pad/privileged_access_ml_linux_high_median_process_command_line_entropy_by_user.toml
- rules/integrations/pad/privileged_access_ml_linux_rare_process_executed_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_high_sum_concurrent_sessions_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_host_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_region_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_source_ip_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_application_assignment_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_lifecycle_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_membership_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_privilege_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_user_lifecycle_management_changes.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_group_management_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_special_logon_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_special_privilege_use_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_user_account_management_events.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_device_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_group_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_privilege_assigned_to_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_region_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_source_ip_by_user.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_host.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_parent_process.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_user.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_host.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_parent_process.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_user.toml

(selectively cherry picked from commit d8a39869c5)
2026-04-22 12:10:39 +00:00
Ruben Groenewoud 1f73d6c076 [New Rules] False Negatives for New BPFDoor Variants (#5939)
* [New Rules] False Negatives for New BPFDoor Variants

* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml

* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml

* IG Additions

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>

(cherry picked from commit 4512ec1735)
2026-04-22 06:07:24 +00:00
Eric Forte a9669bc64f [FR] Workflow Updates for Automatically Bumping Stack Version (#5941)
(cherry picked from commit 67313bcd2a)
2026-04-21 15:53:02 +00:00
Jonhnathan e5f77aff00 [Rule Tuning] Update MDE tags to "Microsoft Defender XDR" (#5927)
* [Rule Tuning] Fix MS Defender XDR tag

* bump upodated_date

(cherry picked from commit 8d25a7ddce)
2026-04-20 22:59:42 +00:00
Samirbous 96762c8bf7 [Tuning] LSASS Process Access via Windows API (#5807)
* Update credential_access_lsass_openprocess_api.toml

* Update credential_access_lsass_openprocess_api.toml
2026-04-20 18:47:45 -04:00
Eric Forte 810db8e70c [Rule Tuning] Abnormally Large DNS Response (#5922)
* Refine event dataset and remove flag on connection type

(cherry picked from commit b2e4925c7f)
2026-04-20 13:32:04 +00:00
Mika Ayenson, PhD 532b8931e1 [Docs] Refresh DEX Philosophy (#5933)
* refresh dex philosophy

* version bump

* Apply suggestions from code review

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* final updates

---------

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit ff73f13446)
2026-04-10 21:43:58 +00:00
Terrance DeJesus 71906a90cc [Rule Tuning] Change event.dataset to data_stream.dataset (#5943)
* [Rule Tuning] Change event.dataset to data_stream.dataset

* updating ESQL field names

(cherry picked from commit deab1c0161)
2026-04-10 16:31:57 +00:00
Eric Forte 606a8eefac [FR] [DAC] Initial Yaml Support (#5821)
* Initial Yaml Support

(cherry picked from commit 9736407ef3)
2026-04-10 15:32:58 +00:00
Jonhnathan 62e6ca44df [Rule Tuning] Process Created with an Elevated Token (#5934)
(cherry picked from commit a9d0d79a5b)
2026-04-10 14:50:59 +00:00
Eric Forte a6a6a54c4d [Bug] Small bugfix to address update navigator edge case (#5942)
* [Bug] Small bugfix to address update navigator edge case

(cherry picked from commit 984be4a1ac)
2026-04-10 12:57:52 +00:00
Eric Forte 6233d72021 [FR] Load ECS mapping based on supplied stack version (#5925)
* Load ECS mapping based on supplied stack version

(cherry picked from commit 1503976d10)
2026-04-09 16:44:13 +00:00
Martijn Laarman 2ab7822e0c Migrate docs workflows from preview-build to docs-actions (#5897)
Moves docs CI/CD from elastic/docs-builder to elastic/docs-actions.
Part of elastic/docs-eng-team#474

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 2e8ff76172)
2026-04-09 13:24:23 +00:00
Samirbous f38552e22f Update persistence_python_launch_agent_or_daemon_creation_first_occurrence.toml (#5937)
(cherry picked from commit b5e5822c1f)
2026-04-08 21:15:24 +00:00
github-actions[bot] 8fdebb28e1 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5930)
(cherry picked from commit c601edfbb3)
integration-v9.3.8
2026-04-08 14:18:11 +00:00
Samirbous a71b1ec9fc Update command_and_control_rmm_after_msi_install.toml (#5901)
(cherry picked from commit 7fcbec380b)
2026-04-08 13:05:01 +00:00
Jonhnathan 572c2415e1 [Rule Deprecation] SUNBURST Command and Control Activity (#5928)
(cherry picked from commit 09e5bf04f4)
2026-04-08 12:29:07 +00:00
Mika Ayenson, PhD 3352954e9b [Rule Tuning] Misc GenAI Rules (#5929)
(cherry picked from commit 9999336f5e)
2026-04-08 12:09:20 +00:00
github-actions[bot] af299e0eba Lock versions for releases: 8.19,9.1,9.2,9.3 (#5926)
(cherry picked from commit 88bc42265f)
2026-04-07 12:18:54 +00:00
Isai ba0ce2762e [New Rules] AWS IAM Long-Term Creds Abuse Coverage (#5924)
* [New Rules] AWS Long-Term Creds Abuse Coverage

This adds a two-layer approach to long-term IAM access key (AKIA*) abuse, aligned with reporting on stolen or leaked keys often abused as seen in Kudelski Security — Trivy supply-chain report.

### Layer 1 — AWS Long-Term Access Key First Seen from Source IP (9f8e3c5e-f72e-4e91-93f6-e98a4fae3e4f)
New Terms on CloudTrail when a given AKIA succeeds from a new `source.ip` in the history window.
Goal: catch novel use of a durable key (travel, new egress, or attacker infrastructure).

### Layer 2 — AWS Long-Term Access Key Correlated with Elevated Detection Alerts
Higher-order rule on open alerts that requires both the Layer 1 rule and at least one other open alert on the same `source.ip` at medium+ severity (or equivalent risk score).
Goal: raise priority when “new IP for this key” happens together with stronger, post-compromise-style signals.

The higher-order rule correlates on `source.ip` in .alerts-security.* index. In testing, I chose to tie the same sessions together using `source.ip` vs `access_key.id` because the alerts index did not expose this field for queries.

Screenshots below show testing that verified the approach. The same operator/session across Layer 1 rule, the sibling alert, and the Layer 2 correlation rule for two separate lab scenarios (e.g. a high-severity sibling rule and a  medium-severity sibling rule).

* adding IAM to rule names

* removing unnecessary ref

* Fixed Mitre tactics and tags

* [New Rules] AWS IAM Long-Term Creds Abuse Coverage

Adding min_stack to rule using the field user.entity.id, we determined AWS version 4.7.0 is compatible with Kibana versions '^8.19.4 || ^9.1.4'. We reverted the initial PR and this one adds the min_stack_version.

Original PR: - https://github.com/elastic/detection-rules/pull/5918
Revert PR: - https://github.com/elastic/detection-rules/pull/5923

(cherry picked from commit c99dc2f4cc)
2026-04-06 19:19:28 +00:00
Isai 90c3a0760b Revert "[New Rules] AWS IAM Long-Term Creds Abuse Coverage (#5918)" (#5923)
This reverts commit a6d31d7dfd.

(cherry picked from commit 2d2ef5f5b1)
2026-04-06 18:34:23 +00:00
Jonhnathan 0338f2f6c7 [Rule Tuning] Windows High-Severity Rules Revamp - 2 (#5900)
* [Rule Tuning] Windows High-Severity Rules Revamp - 2

* ++

* Compress guides

* ++

* ++

(cherry picked from commit a950f4738e)
2026-04-06 16:10:16 +00:00
Jonhnathan 12ff1b4f0d [Rule Tuning] Windows High-Severity Rules Revamp - 1 (#5899)
* [Rule Tuning] Windows High-Severity Rules Revamp - 1

* ++

* Guide compression

* ++

* revert unit test removal

* Apply suggestion from @w0rk3r

* Update command_and_control_headless_browser.toml

---------

Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>

(cherry picked from commit 2c42c12c26)
2026-04-06 15:34:49 +00:00
Isai a32792a8dd [New Rules] AWS IAM Long-Term Creds Abuse Coverage (#5918)
* [New Rules] AWS Long-Term Creds Abuse Coverage

This adds a two-layer approach to long-term IAM access key (AKIA*) abuse, aligned with reporting on stolen or leaked keys often abused as seen in Kudelski Security — Trivy supply-chain report.

### Layer 1 — AWS Long-Term Access Key First Seen from Source IP (9f8e3c5e-f72e-4e91-93f6-e98a4fae3e4f)
New Terms on CloudTrail when a given AKIA succeeds from a new `source.ip` in the history window.
Goal: catch novel use of a durable key (travel, new egress, or attacker infrastructure).

### Layer 2 — AWS Long-Term Access Key Correlated with Elevated Detection Alerts
Higher-order rule on open alerts that requires both the Layer 1 rule and at least one other open alert on the same `source.ip` at medium+ severity (or equivalent risk score).
Goal: raise priority when “new IP for this key” happens together with stronger, post-compromise-style signals.

The higher-order rule correlates on `source.ip` in .alerts-security.* index. In testing, I chose to tie the same sessions together using `source.ip` vs `access_key.id` because the alerts index did not expose this field for queries.

Screenshots below show testing that verified the approach. The same operator/session across Layer 1 rule, the sibling alert, and the Layer 2 correlation rule for two separate lab scenarios (e.g. a high-severity sibling rule and a  medium-severity sibling rule).

* adding IAM to rule names

* removing unnecessary ref

* Fixed Mitre tactics and tags

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit a6d31d7dfd)
2026-04-06 14:40:17 +00:00
Isai 5dd939d41d [New Rule] AWS S3 Rapid Bucket Posture API Calls from a Single Principal (#5911)
* [New Rule] AWS S3 Rapid Bucket Posture API Calls from a Single Principal

Detects the same principal (`aws.cloudtrail.user_identity.arn`) from the same `source.ip` successfully calling a tight set of read-only S3 management APIs: ``` GetBucketAcl, GetBucketPublicAccessBlock, GetBucketPolicy, GetBucketPolicyStatus, GetBucketVersioning ``` against more than 15 distinct buckets (`aws.cloudtrail.resources.arn`) within a 10-second window.

The idea is grounded in cloud reconnaissance and scanner-style behavior discussed in Kudelski Security’s analysis of the Trivy supply chain story and related cloud activity. It explicitly called out automated assessment tooling and posture-oriented API use across ~24 buckets in a short time. It also highlighted the user's blind spot in telemetry with no Data events captured for S3 buckets. So would need to rely on management APIs for detection.

All our existing detections related to S3 rely on Data events and we have no explicit detections for scanner style recon sweeps as described in this threat report.

### Rule Design

- ES|QL with date_trunc(10 seconds, …) and count_distinct(aws.cloudtrail.resources.arn) grouped by time bucket, identity ARN, and source.ip.
- Management level API calls that are commonly used to identify bucket posture including public accessibility status and whether or not versioning is enabled (necessary info for ransomeware objectives)
- Excludes AWSService, requires source.ip, non-null aws.cloudtrail.resources.arn and user_identity.arn, and session_credential_from_console IS NULL to capture programmatic sessions over console behavior.
- Threshold 15 after evaluating rule in production environment to reduce noise from benign scanners and automation.
- low severity as this rule is FP prone until users add exclusions for known scanner behaviors specific to their environment

* correcting highlighted fields

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit ca821414a4)
2026-04-06 14:10:23 +00:00
Jonhnathan 1056969ce6 Remove OSQuery/Investigate Plugin disclaimer enforcement (#5921)
* Remove OSQuery/Investigate Plugin disclaimer enforcement

* Update pyproject.toml

(cherry picked from commit c78c6363b0)
2026-04-06 13:56:54 +00:00
Terrance DeJesus 3555a1e455 [Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field (#5894)
* [Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field
Fixes #5893

* adding non-admin consented filter

* converting to ESQL

* additional query adjustments

* adjusted query KEEP

* updating non-ecs

* Apply suggestion from @terrancedejesus

(cherry picked from commit 48128c1c66)
2026-04-06 13:44:00 +00:00
Terrance DeJesus 14ec5c52be [Rule Tuning] M365 Identity OAuth Illicit Consent Grant by Rare Client and User (#5917)
Fixes #5916

(cherry picked from commit 6f23fb8d08)
2026-04-06 13:33:50 +00:00
Terrance DeJesus 5bc59225eb [Rule Tuning] Entra ID Service Principal with Unusual Source ASN (#5915)
* [Rule Tuning] Entra ID Service Principal with Unusual Source ASN
Fixes #5914

* optimizing query

(cherry picked from commit 1924fc3fae)
2026-04-06 13:03:24 +00:00
Jonhnathan f1fe69c65c [Rule Tuning] Misc Windows (#5906)
(cherry picked from commit 0a8c89d3f5)
2026-04-06 12:46:25 +00:00
shashank-elastic b212b283f7 Monthly Manifest and Schema Updation (#5920)
(cherry picked from commit 199a4d6160)
2026-04-06 12:09:16 +00:00
Isai d2997a4fe1 [New Rule][Rule Tuning] AWS Organizations/Account Discovery Coverage (#5910)
* [New Rule][Rule Tuning] AWS Organizations/Account Discovery Coverage

In response to the supply chain attack highlighted in (Kudelski’s Trivy / TeamPCP analysis)[https://kudelskisecurity.com/research/investigating-two-variants-of-the-trivy-supply-chain-compromise], I've added coverage for AWS Organization and Account reconnaissance which was called out in the research.

### AWS Discovery API Calls via CLI from a Single Resource
- Expanded our existing Multi-service discovery rule to include `event.provider: oraganizations.amazonaws.com`
- added the new `aws.cloudtrail.session_credential_from_console` field to exclude console behavior from this rule, and added appropriate `min_stack` to account for introduction of the field.

GAP: This rule detects aws-cli usage only. In the mentioned reference, attackers used Botocore and Boto3 tooling for this recon activity.

SOLUTION:

### AWS Account Discovery By Rare User
- Created a new Discovery rule focused solely on Organization/Account reconnaissance.
- Made it a new terms rule to reduce false positive noise from common behavior that might be seen using Boto3 or Botocore tooling.
- excluded console session behavior and service account behavior

Testing:
- Ran PACU's organization__enum module
- created a script that can be run to validate the query
- plenty of test data in our stack to run the query against

* Update rules/integrations/aws/discovery_organization_discovery_by_rare_user.toml

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

---------

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit c0b852a23d)
2026-04-03 18:58:03 +00:00
Terrance DeJesus c938842db2 [Rule Tuning] AWS suspicious user agents (TruffleHog, Kali CLI/Boto3) (#5902)
* Expand AWS CloudTrail user-agent rule for TruffleHog and Kali

- Rename rule file to initial_access_suspicious_user_agent_detected_in_cloudtrail.toml
- Rule name: AWS Suspicious User Agent Fingerprint
- Match TruffleHog in user_agent.original (successful API calls)
- Retain Kali Linux distrib#kali fingerprint for aws-cli/Boto3
- Refresh narrative and references (incl. Kudelski Trivy supply-chain analysis)

Same rule_id f80ea920-f6f5-4c8a-9761-84ac97ec0cb2.

Made-with: Cursor

* Apply suggestion from @terrancedejesus

(cherry picked from commit ae5ecd5346)
2026-04-03 15:54:39 +00:00
Ruben Groenewoud cd41b5e7f0 [Rule Tuning] Potential snap-confine Privilege Escalation (#5889)
* [Rule Tuning] Potential snap-confine Privilege Escalation via CVE-2026-3888

* ++

(cherry picked from commit 778781cc13)
2026-04-02 09:24:56 +00:00
Mika Ayenson, PhD b322b7505c [Rule Tuning] Add Supplemental Mitre Mappings (#5876)
---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>

(cherry picked from commit 8993d1450b)
2026-04-01 14:16:50 +00:00
Samirbous 9eca1ea68d [New] Elastic Defend Alert from Package Manager Install Ancestry (#5905)
* [New] Elastic Defend Alert from Package Manager Install Ancestry

Detects Elastic Defend alerts (behavior, malicious file, memory signature, shellcode) where the alerted process has a package-manager install context in its ancestry: npm (Node.js), PyPI (pip / Python / uv), or Rust (cargo). Install-time spawn chains are a common path for supply-chain and postinstall abuse; this Higher-Order rule surfaces Defend alerts
whose process tree includes such activity for prioritization.

* Update initial_access_elastic_defend_alert_package_manager_ancestor.toml

* Update rules/cross-platform/initial_access_elastic_defend_alert_package_manager_ancestor.toml

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* Update rules/cross-platform/initial_access_elastic_defend_alert_package_manager_ancestor.toml

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* Update initial_access_elastic_defend_alert_package_manager_ancestor.toml

---------

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 116f48ccda)
2026-03-31 22:37:24 +00:00
Ruben Groenewoud b59529c2fa [Rule Tuning] Curl or Wget Spawned via Node.js (#5904)
(cherry picked from commit 62b60f9a78)
2026-03-31 16:40:45 +00:00
Terrance DeJesus de285c8423 [Rule Tuning] M365 Identity Login from Atypical Travel Location - Reduce FP Noise (#5866)
* [Rule Tuning] M365 Identity Login from Atypical Travel Location - Reduce FP Noise
Fixes #5865

* removing CMSI for FNs

(cherry picked from commit c932ececd9)
2026-03-26 20:07:24 +00:00
Terrance DeJesus 8fc3cbade7 [Rule Tuning] Entra ID OAuth User Impersonation to Microsoft Graph (#5864)
* [Rule Tuning] Entra ID OAuth User Impersonation to Microsoft Graph
Fixes #5863

* Apply suggestion from @eric-forte-elastic

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* make sure sign in sources are not null

---------

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 60beaff33f)
2026-03-26 19:52:27 +00:00
github-actions[bot] 518496c9d7 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5888)
* Locked versions for releases: 8.19,9.1,9.2,9.3

* Update pyproject.toml

---------

Co-authored-by: Mikaayenson <Mikaayenson@users.noreply.github.com>

(cherry picked from commit d9890db6ff)
integration-v9.3.7
2026-03-26 17:35:40 +00:00
Ruben Groenewoud 2d4944d11b [New Rules] LiteLLM & Trivy TeamPCP Compromise (#5885)
* [New Rules] LiteLLM & Trivy TeamPCP Compromise

* ++

* Apply suggestion from @Samirbous

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* Apply suggestion from @Samirbous

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* ++

* ++

* Update rules/cross-platform/collection_data_encrypted_via_openssl.toml

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* Update rules/cross-platform/collection_data_encrypted_via_openssl.toml

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

* ++

* ++

* ++

* ++

* Update rules/cross-platform/execution_suspicious_python_command_execution.toml

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* Update rules/cross-platform/execution_suspicious_python_command_execution.toml

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* Update rules/cross-platform/defense_evasion_data_encrypted_via_openssl.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update rules/cross-platform/defense_evasion_data_encrypted_via_openssl.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* ++

* ++

* ++

* ++

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit c6f843ef9d)
2026-03-26 16:20:37 +00:00
Terrance DeJesus 711e9c00d6 rule tuning add ICP blockchain indicator (#5887)
(cherry picked from commit a8033e14aa)
2026-03-26 16:13:49 +00:00
Ruben Groenewoud 566e1fbbd8 [Rule Tuning] Python Path File (pth) Creation (#5880)
* [Rule Tuning] Python Path File (pth) Creation

* ++

* ++

* ++

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit befd78524e)
2026-03-26 16:01:06 +00:00
Terrance DeJesus 6e1acda7f2 [New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme (#5878)
* [New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme
Fixes #5877

* adding microsoft_exchange_online_message_trace to manifests/schemas; bumping patch

* updated mitre

* Update rules/integrations/microsoft_exchange_online_message_trace/initial_access_azure_monitor_callback_phishing_email.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* bumping patch

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit cd19b25485)
2026-03-26 15:54:19 +00:00
Samirbous 0bb91a2ff0 [Tuning] Multiple Cloud Secrets Accessed by Source Address (#5884)
* Update credential_access_multi_could_secrets_via_api.toml

* Update credential_access_multi_could_secrets_via_api.toml

* Update credential_access_multi_could_secrets_via_api.toml

* Apply suggestion from @Mikaayenson

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Apply suggestion from @Mikaayenson

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit 06ea087363)
2026-03-26 15:52:55 +00:00
Terrance DeJesus 7c2a7310a8 [Rule Tuning] Entra ID Federation Abuse to Production (#5881)
* [Rule Tuning] Entra ID Federation Abuse to Production

* adjusted file name

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit a08d6b4ff7)
2026-03-26 15:49:18 +00:00
Terrance DeJesus 8fc4a7df98 [Rule Tuning] M365 SharePoint/OneDrive File Access via PowerShell - Convert to new_terms (#5873)
Fixes #5872

(cherry picked from commit 18a28762bf)
2026-03-26 15:32:27 +00:00
Samirbous b7bf42afa6 [Tuning] Expand compatibility to extra OS (#5883)
* Update and rename exfiltration_potential_curl_data_exfiltration.toml to exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update exfiltration_potential_curl_data_exfiltration.toml

* Update execution_kubernetes_direct_api_request_via_curl_or_wget.toml

* ++

* ++

* Update rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update rules/cross-platform/exfiltration_potential_curl_data_exfiltration.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit 5d5e1d9ca4)
2026-03-26 12:14:12 +00:00