Samirbous
cdd9dbfcdb
[Tuning/New] Namespace Manipulation Using Unshare ( #6024 )
...
* Update privilege_escalation_unshare_namespace_manipulation.toml
* Create privilege_escalation_unshare_namespace_manip.toml
* Apply suggestion from @Aegrah
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update privilege_escalation_unshare_namespace_manip.toml
* Update privilege_escalation_unshare_namespace_manipulation.toml
* Update privilege_escalation_unshare_namespace_manipulation.toml
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit ba8fa3ef0f )
2026-05-01 14:32:58 +00:00
Mika Ayenson, PhD
96a78fd024
Revert "[Tuning] Namespace Manipulation Using Unshare ( #5989 )" ( #6023 )
...
This reverts commit 175e043adf .
(cherry picked from commit a1458f0fd0 )
2026-05-01 13:27:39 +00:00
Samirbous
16e7f82d5f
[Tuning] Namespace Manipulation Using Unshare ( #5989 )
...
* Update privilege_escalation_unshare_namespace_manipulation.toml
* Update privilege_escalation_unshare_namespace_manipulation.toml
(cherry picked from commit 175e043adf )
2026-05-01 10:20:30 +00:00
Samirbous
26c66ad09c
[New/Tuning] Linux LPE via SUID Shell ( #5980 )
...
* [New] Kubernetes Pod Exec with Curl or Wget to HTTPS
Detects pod or attach `exec` API calls where the decoded request query implies curl or wget fetching an https URL (avoid noisy local http services).
* Create execution_kubernetes_pod_exec_potential_reverse_shell.toml
* Update execution_kubernetes_pod_exec_curl_wget_https.toml
* Update execution_kubernetes_pod_exec_potential_reverse_shell.toml
* ++
* ++
* Add auditd rule for root-effective shell -p outside system paths; extend SUID/SGID exploitation coverage.
Made-with: Cursor
* Revert "++"
This reverts commit eb5631d80e .
* Revert "++"
This reverts commit 2d2c34ca21 .
* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_curl_wget_https.toml
* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_potential_reverse_shell.toml
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
* Update rules/linux/privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
---------
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
(cherry picked from commit 6b3b84ca38 )
2026-05-01 09:54:56 +00:00
Ruben Groenewoud
f25072c389
[Rule Tuning] Privilege Escalation via SUID/SGID ( #6017 )
...
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
(cherry picked from commit 8dc3fef270 )
2026-05-01 08:12:13 +00:00
Samirbous
2e1f3a66e7
[New] Suspicious SUID Binary Execution ( #6018 )
...
* [New] Suspicious SUDI Binary Execution
Detects execution of common privilege elevation helpers (su, sudo, pkexec, passwd, chsh, newgrp) under the root effective user when the real user and parent user are not root, combined with minimal argument counts and suspicious parent context (interpreters, short shell -c invocations, or parents running from user-writable paths) :
* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update privilege_escalation_suspicious_sudi_binary_execution.toml
* Update privilege_escalation_suspicious_sudi_binary_execution.toml
* Rename privilege_escalation_suspicious_sudi_binary_execution.toml to privilege_escalation_suspicious_suid_binary_execution.toml
* Update privilege_escalation_suspicious_suid_binary_execution.toml
* Update privilege_escalation_suspicious_suid_binary_execution.toml
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit f0467c8bed )
2026-04-30 16:41:53 +00:00
Eric Forte
34c6386ed7
[New] Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket ( #6015 )
...
* initial draft rule too noisy atm
* Switch To Sequence Rule
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 3371938045 )
2026-04-30 16:27:45 +00:00
Ruben Groenewoud
1f73d6c076
[New Rules] False Negatives for New BPFDoor Variants ( #5939 )
...
* [New Rules] False Negatives for New BPFDoor Variants
* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml
* Update defense_evasion_file_creation_world_writeable_dir_by_unusual_process.toml
* IG Additions
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit 4512ec1735 )
2026-04-22 06:07:24 +00:00
Terrance DeJesus
71906a90cc
[Rule Tuning] Change event.dataset to data_stream.dataset ( #5943 )
...
* [Rule Tuning] Change event.dataset to data_stream.dataset
* updating ESQL field names
(cherry picked from commit deab1c0161 )
2026-04-10 16:31:57 +00:00
Ruben Groenewoud
cd41b5e7f0
[Rule Tuning] Potential snap-confine Privilege Escalation ( #5889 )
...
* [Rule Tuning] Potential snap-confine Privilege Escalation via CVE-2026-3888
* ++
(cherry picked from commit 778781cc13 )
2026-04-02 09:24:56 +00:00
Mika Ayenson, PhD
b322b7505c
[Rule Tuning] Add Supplemental Mitre Mappings ( #5876 )
...
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co >
(cherry picked from commit 8993d1450b )
2026-04-01 14:16:50 +00:00
Ruben Groenewoud
566e1fbbd8
[Rule Tuning] Python Path File (pth) Creation ( #5880 )
...
* [Rule Tuning] Python Path File (pth) Creation
* ++
* ++
* ++
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
(cherry picked from commit befd78524e )
2026-03-26 16:01:06 +00:00
Samirbous
b7bf42afa6
[Tuning] Expand compatibility to extra OS ( #5883 )
...
* Update and rename exfiltration_potential_curl_data_exfiltration.toml to exfiltration_potential_curl_data_exfiltration.toml
* Update exfiltration_potential_curl_data_exfiltration.toml
* Update exfiltration_potential_curl_data_exfiltration.toml
* Update exfiltration_potential_curl_data_exfiltration.toml
* Update execution_kubernetes_direct_api_request_via_curl_or_wget.toml
* ++
* ++
* Update rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/discovery_kubectl_secrets_all_namespaces.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/cross-platform/exfiltration_potential_curl_data_exfiltration.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit 5d5e1d9ca4 )
2026-03-26 12:14:12 +00:00
shashank-elastic
fe942003a2
Add investigation guide for database dumping activity ( #5871 )
...
(cherry picked from commit 07ccecb94b )
2026-03-23 16:56:48 +00:00
Ruben Groenewoud
1f5a21524f
[New Rules] AppArmor Exploitation (CrackArmor) ( #5842 )
...
* [New Rule] AppArmor Profile Compilation via apparmor_parser
* [New Rule] Suspicious Write Attempt to AppArmor Policy Management Files
* ++
* 2 more rules for Auditd
* ++
* Update defense_evasion_apparmor_profile_compilation.toml
* Apply suggestion from @Aegrah
* Update rules/linux/defense_evasion_apparmor_profile_compilation.toml
(cherry picked from commit 5216bf2d0c )
2026-03-23 08:41:38 +00:00
Ruben Groenewoud
49a4909788
[New Rule] Potential snap-confine Privilege Escalation via CVE-2026-3888 ( #5845 )
...
* [New Rule] Potential snap-confine Privilege Escalation via CVE-2026-3888
* Added IG
* ++
* ++
* IG fix
(cherry picked from commit de6eb0f10d )
2026-03-20 08:38:15 +00:00
Ruben Groenewoud
23ee0683ab
[New/Tuning] New DB Dump Rule & Tuning wget/curl DRs ( #5832 )
...
* [Rule Tuning] Tuning wget/curl DRs
* [New Rule] Potential Database Dumping Activity
* Update exfiltration_potential_curl_data_exfiltration.toml
* Expand URL patterns in curl data exfiltration rule
* Update rules/linux/exfiltration_potential_wget_data_exfiltration.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Simplify process name conditions for database dumping
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
(cherry picked from commit a4b614c681 )
2026-03-19 13:02:06 +00:00
Ruben Groenewoud
374668a371
[Rule Tuning] Dynamic Linker Copy ( #5841 )
...
(cherry picked from commit 5d3e17eaff )
2026-03-17 16:20:07 +00:00
Ruben Groenewoud
55523469d4
[Rule Tuning] Base64 Decoded Payload Piped to Interpreter ( #5811 )
...
(cherry picked from commit 99bdb22a8d )
2026-03-09 14:10:23 +00:00
Ruben Groenewoud
017e244484
[Rule Tuning] agent.id --> host.id new_terms Key Modification ( #5802 )
...
* [Rule Tuning] `agent.id` --> `host.id` Migration
* Updated_date bump
(cherry picked from commit aaf99b1873 )
2026-03-02 12:28:20 +00:00
Eric Forte
da602f9b29
[Rule Tuning] Telnet Authentication Bypass Rule Tuning ( #5771 )
...
* Add xinetd in process names
(cherry picked from commit 4201fe6f8a )
2026-02-25 20:47:28 +00:00
Ruben Groenewoud
1d150560a2
[New Rules] Kernel Discovery & BPF Load/Tampering via bpftool ( #5743 )
...
* [New Rules] BPF Load & Tampering via bpftool
* Update persistence_bpf_program_or_map_load.toml
* [New Rule] Kernel Instrumentation Discovery via kprobes and tracefs
* Update defense_evasion_bpf_program_tampering.toml
* Update persistence_bpf_program_or_map_load.toml
* Enhance note with investigation and response details
Added detailed investigation guide and response steps for kernel instrumentation discovery via kprobes and tracefs.
(cherry picked from commit c349c8eca7 )
2026-02-23 15:37:33 +00:00
Ruben Groenewoud
eeb5c7b3f3
[New/Tuning] New LKM Load Rule & FN Tuning Tunneling Rules ( #5742 )
...
* [New/Tuning] New LKM Load Rule & FN Tuning Tunneling Rules
* ++
* Update persistence_kernel_module_load_from_unusual_location.toml
* Update persistence_kernel_module_load_from_unusual_location.toml
* Apply suggestion from @Aegrah
* Update persistence_kernel_module_load_from_unusual_location.toml
(cherry picked from commit 56c737c1d0 )
2026-02-23 09:05:40 +00:00
Ruben Groenewoud
f90445047a
[Rule Tuning] Kernel Module Load via Built-in Utility ( #5736 )
...
* [Rule Tuning] Kernel Module Load via Built-in Utility
* Apply suggestion from @eric-forte-elastic
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
* Refine process.args conditions for modprobe
* Refactor notes and references in kernel module load rule
Removed detailed notes and investigation steps related to kernel module loading via insmod utility. Updated note section and added a reference link.
* Update persistence_insmod_kernel_module_load.toml
* Update persistence_insmod_kernel_module_load.toml
* Update kernel module load rule for clarity and tactics
---------
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
(cherry picked from commit e012e88342 )
2026-02-23 08:52:08 +00:00
Ruben Groenewoud
ee49e1fa4b
[Rule Tuning] System Information Discovery via dmidecode from Parent Shell ( #5732 )
...
(cherry picked from commit 0c7e6516f9 )
2026-02-17 16:54:10 +00:00
Ruben Groenewoud
5acf1127de
[Rule Tuning] Adding D4C Compatibility to Compatible Container-Related Rules ( #5685 )
...
* Updated kubernetes.audit.requestObject.spec.containers.image type of text to Keyword
* [Rule Tuning] Adding D4C Compatibility to Compatible Container-Related Rules
(cherry picked from commit 440ff43810 )
2026-02-06 08:42:54 +00:00
Ruben Groenewoud
a3638565e8
[Rule Tuning] Dormant & Deprecated Rule Clean-Up ( #5672 )
...
* Updated kubernetes.audit.requestObject.spec.containers.image type of text to Keyword
* [Rule Tuning] Dormant & Deprecated Rule Clean-Up
* [Rule Tuning] Dormant & Deprecated Rule Clean-Up
* Few more deprecations
* ++
* Update unit test syntax fix
* Update bad bytes
* ++
(cherry picked from commit 3cba3d7982 )
2026-02-05 12:28:34 +00:00
Samirbous
5143c14e51
[Tuning] ESQL Dynamic unique value fields ( #5569 )
...
* [Tuning] Extract dynamic field with 1 value to ECS fields for alerts exclusion
Extract dynamic field with 1 value to ECS fields for alerts exclusion:
Esql.host_id_values -> host.is
Esql.agent_id_values -> agent.id
Esql.host_name_values -> host.name
* Update multiple_alerts_by_host_ip_and_source_ip.toml
* Update newly_observed_elastic_defend_alert.toml
* Update defense_evasion_base64_decoding_activity.toml
* Update discovery_subnet_scanning_activity_from_compromised_host.toml
* Update persistence_web_server_sus_command_execution.toml
* Update persistence_web_server_sus_child_spawned.toml
* Update rules/cross-platform/multiple_alerts_elastic_defend_netsecurity_by_host.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/linux/impact_potential_bruteforce_malware_infection.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/linux/command_and_control_frequent_egress_netcon_from_sus_executable.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Apply suggestions from code review
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/cross-platform/multiple_alerts_elastic_defend_netsecurity_by_host.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/cross-platform/newly_observed_elastic_defend_alert.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/cross-platform/newly_observed_elastic_detection_rule.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update rules/windows/credential_access_rare_webdav_destination.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update credential_access_rare_webdav_destination.toml
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 88e0b14709 )
2026-01-26 16:38:12 +00:00
Ruben Groenewoud
d80d0147f6
[Rule Tuning] Several Community DR Issues ( #5615 )
...
* [Rule Tuning] Suspicious Network Connection via systemd
* [Rule Tuning] Systemd-udevd Rule File Creation
* ++
(cherry picked from commit 6626475119 )
2026-01-26 16:12:48 +00:00
Mika Ayenson, PhD
9b69bc806e
Revert "[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules ( #5578 )" ( #5620 )
...
This reverts commit c608b673bf .
(cherry picked from commit bbe83452b4 )
2026-01-26 14:35:43 +00:00
Ruben Groenewoud
625b6bc531
[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules ( #5578 )
...
* [Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules
* Update manifests & schemas
* [New/Updated] Migrated `process.command_line` --> `process.args` for Compatibility
* Pyproject.toml Patch
* ++
(cherry picked from commit c608b673bf )
2026-01-26 12:31:59 +00:00
Samirbous
3f8b50faf7
[New] Potential Telnet Authentication Bypass (CVE-2026-24061) ( #5612 )
...
* [New] Potential Telnet Authentication Bypass (CVE-2026-24061)
https://www.safebreach.com/blog/safebreach-labs-root-cause-analysis-and-poc-exploit-for-cve-2026-24061/ "
https://security-tracker.debian.org/tracker/CVE-2026-24061
* Update lateral_movement_telnet_auth_bypass_via_envar.toml
* Update lateral_movement_telnet_auth_bypass_via_envar.toml
* Update lateral_movement_telnet_auth_bypass_via_envar.toml
* Apply suggestion from @Aegrah
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update initial_access_telnet_auth_bypass_via_user_envar.toml
* Update rules/linux/initial_access_telnet_auth_bypass_via_user_envar.toml
* added rule for auditd
* Update rules/linux/initial_access_telnet_auth_bypass_envar_auditd.toml
* Update rules/linux/initial_access_telnet_auth_bypass_envar_auditd.toml
* Update initial_access_telnet_auth_bypass_envar_auditd.toml
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit 3497c7b0b5 )
2026-01-26 10:22:09 +00:00
ailiffa
6d33767506
[Rule Tuning] Potential Disabling of AppArmor - Restore AppArmor service filters ( #5574 )
...
(cherry picked from commit e459d8c25a )
2026-01-19 12:23:12 +00:00
shashank-elastic
9b2b1303ce
Prep for Release 9.3 ( #5548 )
...
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit 1ce072a4e5 )
2026-01-12 15:41:28 +00:00
Ruben Groenewoud
11769a4be3
[New/Tuning] Several New Linux Rules ( #5531 )
...
* [New/Tuning] Several New Linux Rules
* Update collection_potential_video_recording_or_screenshot_activity.toml
* Update discovery_dmidecode_system_discovery.toml
* Update rules/linux/collection_potential_audio_recording_activity.toml
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
* Update exfiltration_potential_wget_data_exfiltration.toml
* [New Rule] Linux User or Group Deletion
---------
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
2026-01-08 16:00:50 +01:00
Ruben Groenewoud
ee936cb154
[New Rule] Potential Password Spraying Attack via SSH ( #5515 )
...
* [New Rule] Potential Password Spraying Attack via SSH
* ++
* Update rules/linux/credential_access_potential_password_spraying_attack.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
* Update credential_access_potential_password_spraying_attack.toml
* Update credential_access_potential_password_spraying_attack.toml
* Change time bucket duration from 1 to 5 minutes
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2026-01-08 13:43:52 +01:00
Ruben Groenewoud
1c1632e0b9
[Rule Tuning] Linux DR Tuning - 3 ( #5483 )
...
* [Rule Tuning] Linux DR Tuning - 3
* Update rules/linux/credential_access_aws_creds_search_inside_container.toml
* Adjust thresholds and expand event action handling
* Update credential_access_potential_linux_ssh_bruteforce_external.toml
* Increase threshold for SSH brute force detection
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update credential_access_ssh_backdoor_log.toml
Removed 'auditbeat-*' from the index list.
* Refactor credential access rule for clarity
Removed redundant event.action expansion and filtering logic.
* Refactor ESQL query for SSH brute force detection
Refactor ESQL query to improve readability and maintainability by moving the event.action expansion and filtering logic.
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update credential_access_potential_successful_linux_ftp_bruteforce.toml
* Update credential_access_potential_successful_linux_rdp_bruteforce.toml
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Add time window truncation to bruteforce rule
* Add time window truncation to SSH brute force rule
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update SSH brute force detection rule to EQL
* Update CIDR match conditions for SSH brute force rule
* Update EQL query for SSH brute force detection
2026-01-08 13:32:43 +01:00
Ruben Groenewoud
e1698890a4
[Rule Tuning] Linux DR Tuning - 7 ( #5504 )
...
* [Rule Tuning] Linux DR Tuning - 7
* Update execution_egress_connection_from_entrypoint_in_container.toml
* Update execution_kubernetes_direct_api_request_via_curl_or_wget.toml
* Update rules/linux/execution_perl_tty_shell.toml
* Update execution_perl_tty_shell.toml
* Update rules/linux/execution_unix_socket_communication.toml
* Update execution_file_made_executable_via_chmod_inside_container.toml
* Remove duplicate Crowdstrike data source entry
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-08 11:10:46 +01:00
Ruben Groenewoud
ccd3f70ee8
[Rule Tuning] Linux DR Tuning - 6 ( #5497 )
...
* [Rule Tuning] Linux DR Tuning - 6
* Fix syntax error in discovery_esxi_software_via_grep.toml
* Update discovery_pam_version_discovery.toml
* Update discovery_virtual_machine_fingerprinting.toml
* Revise investigation title for kernel module enumeration
Updated the title of the investigation section to clarify focus on unusual kernel module enumeration.
* Update discovery_port_scanning_activity_from_compromised_host.toml
* Enhance ESQL query for subnet scanning detection
Updated ESQL query to include additional fields and conditions for better analysis of connection attempts from compromised hosts.
* Remove Elastic Endgame data source from rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-08 10:45:32 +01:00
Ruben Groenewoud
c2747b0b29
[Rule Tuning] Linux DR Tuning - 4 ( #5484 )
...
* [Rule Tuning] Linux DR Tuning - 4
* Update defense_evasion_file_mod_writable_dir.toml
* Update command_and_control_frequent_egress_netcon_from_sus_executable.toml
* Remove duplicate host.name entry in TOML file
* Fix formatting in defense_evasion_file_mod_writable_dir.toml
* Update command_and_control_frequent_egress_netcon_from_sus_executable.toml
* Add additional fields to base64 decoding activity rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-08 10:11:05 +01:00
Ruben Groenewoud
b13afcdeaa
[Rule Tuning] Linux DR Tuning - 8 ( #5505 )
...
* [Rule Tuning] Linux DR Tuning - 8
* Revise investigation guide for THC tool downloads
Updated investigation guide to reflect THC tool instead of SSH-IT worm. Enhanced description for clarity.
* Update exfiltration_unusual_file_transfer_utility_launched.toml
* Refine ESQL query for brute force malware detection
Updated the query to include additional fields and modified the conditions for filtering events.
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-08 10:01:11 +01:00
Ruben Groenewoud
d968f62a5a
[Rule Tuning] Linux DR Tuning - 10 ( #5510 )
...
* [Rule Tuning] Linux DR Tuning - 10
* Update persistence_udev_rule_creation.toml
* Refactor ESQL query for Linux process events
* Refactor query in persistence_web_server_sus_command_execution rule
Removed unnecessary fields from the query and added new fields for event dataset and data stream namespace.
* Update persistence_systemd_netcon.toml
* Update persistence_web_server_sus_child_spawned.toml
* Refactor process.parent.name conditions in TOML file
* Update persistence_web_server_unusual_command_execution.toml
* Update persistence_web_server_unusual_command_execution.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-08 09:32:57 +01:00
Ruben Groenewoud
80ee91b0f2
[Rule Tuning] Linux DR Tuning - 11 ( #5511 )
...
* [Rule Tuning] Linux DR Tuning - 11
* Update privilege_escalation_potential_suid_sgid_exploitation.toml
* Update rules/linux/privilege_escalation_suspicious_uid_guid_elevation.toml
* Update privilege_escalation_docker_escape_via_nsenter.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-07 16:31:13 +01:00
Ruben Groenewoud
a973da1a6b
[Rule Tuning] Linux DR Tuning - 9 ( #5508 )
...
* [Rule Tuning] Linux DR Tuning - 9
* Update rules/linux/persistence_apt_package_manager_file_creation.toml
* Fix formatting in persistence_boot_file_copy.toml
* Update persistence_chkconfig_service_add.toml
* Change user.id values to string format in TOML
* Fix condition for Java process working directory
* Fix logical operator in OpenSSL passwd hash rule
* Fix syntax for working_directory check
* Fix condition for original file name check
* Update persistence_web_server_unusual_command_execution.toml
* Add cloud CLI tools to persistence rules
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-07 16:18:38 +01:00
Ruben Groenewoud
473df70fbb
[Rule Tuning] Linux DR Tuning - 5 ( #5494 )
...
* [Rule Tuning] Linux DR Tuning - 5
* Fix query syntax for shared object detection rule
* Update defense_evasion_kernel_module_removal.toml
* Fix condition for process working directory check
* Refactor query in defense_evasion_symlink_binary rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-07 15:55:06 +01:00
Ruben Groenewoud
066096f766
[Rule Tuning] Linux DR Tuning - 2 ( #5481 )
...
* [Rule Tuning] Linux DR Tuning - 2
* Update command_and_control_linux_proxychains_activity.toml
2026-01-06 17:00:55 +01:00
Ruben Groenewoud
019c263ed2
[Rule Tuning] Linux DR Tuning - 1 ( #5122 )
...
* [Rule Tuning] Linux DR Tuning - 1
* Added integrations
* Update command_and_control_git_repo_or_file_download_to_sus_dir.toml
* Update collection_linux_clipboard_activity.toml
* Update collection_linux_clipboard_activity.toml
* Update rules/linux/command_and_control_aws_cli_endpoint_url_used.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Update collection_linux_clipboard_activity.toml
* Update rules/linux/command_and_control_aws_cli_endpoint_url_used.toml
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
2026-01-06 16:18:04 +01:00
Ruben Groenewoud
5bc834bfc6
[Rule Tuning] Shared Object Created or Changed by Previously Unknown … ( #5469 )
...
* [Rule Tuning] Shared Object Created or Changed by Previously Unknown Process
* Update rules/linux/persistence_shared_object_creation.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
2025-12-19 14:32:31 +01:00
Samirbous
b996a29451
[Tuning] Diverse Rules Tuning ( #5482 )
...
* [Tuning] Diverse Rules Tuning
* Update persistence_shell_profile_modification.toml
* Update defense_evasion_ml_suspicious_windows_event_low_probability.toml
* Update defense_evasion_ml_suspicious_windows_event_high_probability.toml
* Update defense_evasion_ml_suspicious_windows_event_high_probability.toml
* ++
* Update persistence_suspicious_ssh_execution_xzbackdoor.toml
* Update persistence_suspicious_ssh_execution_xzbackdoor.toml
* Update credential_access_potential_linux_ssh_bruteforce_internal.toml
* Update persistence_shell_profile_modification.toml
* Revert "Update credential_access_potential_linux_ssh_bruteforce_internal.toml"
This reverts commit bad889a30d .
* Update persistence_web_server_sus_destination_port.toml
* Update defense_evasion_ml_suspicious_windows_event_high_probability.toml
* Update defense_evasion_ml_suspicious_windows_event_low_probability.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
2025-12-18 15:30:12 +00:00
Ruben Groenewoud
a16307ecff
[New/Tuning] Linux Tunneling Rules ( #5452 )
2025-12-15 10:44:08 +01:00