shashank-elastic
|
03c20ec798
|
Fix pipe characters in rule descriptions (#4893)
(cherry picked from commit b70792082a)
|
2025-07-10 09:43:20 +00:00 |
|
shashank-elastic
|
008dce0c6f
|
Add investigation guides for detection rules (#4886)
(cherry picked from commit 7175b3ab06)
|
2025-07-07 18:57:53 +00:00 |
|
shashank-elastic
|
f036cb90fe
|
Prep 8.19/9.1 (#4869)
* Prep 8.19/9.1 Release
* Download Beats Schema
* Download API Schema
* Download 8.18.3 Beats Schema
* Download Latest Integrations manifest and schema
* Comment old schemas
* Update Patch version
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit 9b292b97ea)
|
2025-07-07 15:30:11 +00:00 |
|
Ruben Groenewoud
|
889ae36b19
|
[New Rule] Kubectl Apply Pod from URL (#4855)
* [New Rule] Kubectl Apply Pod from URL
* Update execution_kubectl_apply_pod_from_url.toml
(cherry picked from commit 715e3f44f4)
|
2025-07-03 08:51:44 +00:00 |
|
Ruben Groenewoud
|
6241e3a058
|
[Rule Tuning] Potential Linux Tunneling and/or Port Forwarding (#4858)
(cherry picked from commit 26e35fd03b)
|
2025-07-03 07:54:51 +00:00 |
|
Ruben Groenewoud
|
2e4c29d32d
|
[New Rule] Kubernetes Sensitive Configuration File Activity (#4849)
* [New Rule] Kubernetes Sensitive Configuration File Activity
* Update rules/linux/persistence_kubernetes_sensitive_file_activity.toml
(cherry picked from commit 3efcd70f8c)
|
2025-07-02 15:20:44 +00:00 |
|
Ruben Groenewoud
|
a9fe0aa68d
|
[New Rule] Potential Kubectl Masquerading (#4832)
* [New Rule] Potential Kubectl Masquerading
* Update defense_evasion_potential_kubectl_masquerading.toml
* ++
* ++
* Update defense_evasion_potential_kubectl_masquerading.toml
* Update rules/linux/defense_evasion_potential_kubectl_masquerading.toml
(cherry picked from commit 0847c32333)
|
2025-06-30 11:52:03 +00:00 |
|
Ruben Groenewoud
|
2e5fb2dc50
|
[New Rule] Kubectl Network Configuration Modification (#4836)
* [New Rule] Kubectl Network Configuration Modification
* ++
(cherry picked from commit bc87ca1d5b)
|
2025-06-30 08:57:39 +00:00 |
|
Ruben Groenewoud
|
346794bf33
|
[New Rule] Kubernetes Direct API Request via Curl or Wget (#4841)
(cherry picked from commit 786542a9d4)
|
2025-06-30 08:38:10 +00:00 |
|
Ruben Groenewoud
|
193ffe1d71
|
[Deprecation] Suspicious File Creation in /etc for Persistence (#4850)
* [Deprecation] Suspicious File Creation in /etc for Persistence
* [Deprecation] Suspicious File Creation in /etc for Persistence
* Update persistence_etc_file_creation.toml
* Fix
(cherry picked from commit 7c07033354)
|
2025-06-27 08:19:26 +00:00 |
|
Ruben Groenewoud
|
ada1f7719f
|
[Rule Tuning] Added Kubernetes Data Source Tag (#4831)
(cherry picked from commit e666cabb3d)
|
2025-06-24 11:23:14 +00:00 |
|
Ruben Groenewoud
|
d52c408483
|
[New Rule] Kubernetes Service Account Secret Access (#4816)
(cherry picked from commit dd4576d127)
|
2025-06-18 04:05:56 +00:00 |
|
Ruben Groenewoud
|
1ac0d74d78
|
[New Rule] Kubeconfig File Creation or Modification (#4810)
* [New Rule] Kubeconfig File Creation or Modification
* Update lateral_movement_kubeconfig_file_activity.toml
(cherry picked from commit 386a4b85eb)
|
2025-06-17 13:05:30 +00:00 |
|
Ruben Groenewoud
|
15d2258858
|
[New Rule] Kubeconfig File Discovery (#4811)
* [New Rule] Kubeconfig File Discovery
* Update discovery_kubeconfig_file_discovery.toml
(cherry picked from commit 6bc808916b)
|
2025-06-17 12:46:58 +00:00 |
|
Ruben Groenewoud
|
0eb37f5b68
|
[Rule Tuning] Container Management Utility Run Inside A Container (#4809)
* [Rule Tuning] Container Management Utility Run Inside A Container
* ++
(cherry picked from commit 103fbf12c8)
|
2025-06-17 12:35:10 +00:00 |
|
Ruben Groenewoud
|
ec9b09c0a4
|
[New Rule] Kubectl Permission Discovery (#4812)
(cherry picked from commit dfd46a09e8)
|
2025-06-17 12:19:08 +00:00 |
|
Ruben Groenewoud
|
fbdb2e10ff
|
[Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765)
(cherry picked from commit b2887e592b)
|
2025-06-05 11:17:01 +00:00 |
|
Ruben Groenewoud
|
ad6972ccb8
|
[Rule Tuning] Shell Configuration Creation or Modification (#4766)
(cherry picked from commit ba9f76c6b5)
|
2025-06-04 09:31:20 +00:00 |
|
Ruben Groenewoud
|
0605d754a3
|
[New Rule] Unusual Exim4 Child Process (#4684)
(cherry picked from commit 3a601a10fb)
|
2025-05-06 17:01:48 +00:00 |
|
Ruben Groenewoud
|
65791ff7c8
|
[New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683)
(cherry picked from commit c145e33f16)
|
2025-05-06 16:43:13 +00:00 |
|
Ruben Groenewoud
|
8fe54e1785
|
[New Rule] Linux Telegram API Request (#4677)
(cherry picked from commit 608e02e27e)
|
2025-05-06 16:27:45 +00:00 |
|
Ruben Groenewoud
|
d196211d68
|
[New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685)
(cherry picked from commit 944428d81e)
|
2025-05-06 15:56:24 +00:00 |
|
Ruben Groenewoud
|
427c617f3b
|
[New Rule] System Binary Symlink to Suspicious Location (#4682)
(cherry picked from commit fdc6b09d54)
|
2025-05-06 12:21:27 +00:00 |
|
Ruben Groenewoud
|
66c8faaa65
|
[New Rule] Suspicious Named Pipe Creation (#4681)
(cherry picked from commit 25dc8498ae)
|
2025-05-06 12:05:07 +00:00 |
|
Ruben Groenewoud
|
e1506c7f6e
|
[New Rule] Suspicious Kernel Feature Activity (#4676)
(cherry picked from commit 8b08795e00)
|
2025-05-06 11:48:07 +00:00 |
|
Ruben Groenewoud
|
453826355a
|
[New Rule] Potential Data Exfiltration Through Curl (#4678)
(cherry picked from commit 0193af2842)
|
2025-05-06 11:32:34 +00:00 |
|
Ruben Groenewoud
|
0855f2b198
|
[New/Tuning] Potential Hex Payload Execution via Command-Line (#4675)
(cherry picked from commit 4030de9295)
|
2025-05-06 11:03:19 +00:00 |
|
Ruben Groenewoud
|
261b6a2a59
|
[New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674)
(cherry picked from commit eb3520a63b)
|
2025-05-06 10:47:36 +00:00 |
|
Ruben Groenewoud
|
86cd02217d
|
[New Rule] Git Repository or File Download to Suspicious Directory (#4663)
(cherry picked from commit 403e20c2c6)
|
2025-05-06 09:40:01 +00:00 |
|
Ruben Groenewoud
|
38734aba83
|
[New Rule] Manual Mount Discovery via /etc/exports (#4662)
(cherry picked from commit 3f9e2edcb5)
|
2025-05-06 09:23:28 +00:00 |
|
Ruben Groenewoud
|
552f0acfaf
|
[New Rule] Docker Release File Creation (#4661)
(cherry picked from commit a9e8a78c09)
|
2025-05-06 09:06:09 +00:00 |
|
Ruben Groenewoud
|
8756bb5513
|
[New Rule] Manual Memory Dumping via Proc Filesystem (#4660)
(cherry picked from commit 13cf424ef5)
|
2025-05-06 08:50:39 +00:00 |
|
Ruben Groenewoud
|
a7a7792c69
|
[FN Tuning] Suspicious /proc/maps Discovery (#4659)
(cherry picked from commit c9c41747fc)
|
2025-05-06 08:34:23 +00:00 |
|
Ruben Groenewoud
|
2d7ae8ca50
|
[New Rule] Suspicious Path Mounted (#4664)
(cherry picked from commit 1150271372)
|
2025-05-06 08:17:14 +00:00 |
|
shashank-elastic
|
fd7e14bcd7
|
Refresh ecs, beats, integration manifests & schemas (#4699)
(cherry picked from commit e4856d3c2c)
|
2025-05-05 17:41:00 +00:00 |
|
Ruben Groenewoud
|
e38f15bcf6
|
[New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658)
(cherry picked from commit 18e1103c51)
|
2025-05-05 08:03:40 +00:00 |
|
Jonhnathan
|
e0f689f18e
|
[Rule Tuning] SSH Authorized Keys File Deletion (#4591)
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
(cherry picked from commit 3eed0f5b6a)
|
2025-04-15 15:20:58 +00:00 |
|
Ruben Groenewoud
|
50758935f6
|
[D4C Conversion] Converting Compatible D4C Rules to DR (#4532)
* [D4C Conversion] Converting Compatible D4C Rules to DR
* added host.os.type
* Rename
* Update rules/linux/execution_container_management_binary_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
(cherry picked from commit 3b1f780435)
|
2025-04-10 12:31:24 +00:00 |
|
Ruben Groenewoud
|
2a07268bdb
|
[FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529)
* [FN Tuning] Shared Object Created or Changed by Previously Unknown Process
* Update process exclusions in TOML file
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>
(cherry picked from commit 05c9f6bbdb)
|
2025-04-08 16:23:58 +00:00 |
|
shashank-elastic
|
a0538f2ce9
|
Add investigation guides (#4600)
(cherry picked from commit 3966981dae)
|
2025-04-07 15:55:32 +00:00 |
|
Jonhnathan
|
182d9e6c47
|
[Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules (#4592)
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
(cherry picked from commit 9577d53284)
|
2025-04-07 15:04:31 +00:00 |
|
shashank-elastic
|
a1dd22efbe
|
Prep for Release 9.0 (#4550)
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit 059d7efa25)
|
2025-03-20 15:07:35 +00:00 |
|
Ruben Groenewoud
|
d7d8c414ec
|
[New Rule] File Creation in /var/log via Suspicious Process (#4528)
* [New Rule] File Creation in /var/log via Suspicious Process
* ++
* ++
|
2025-03-12 12:50:48 +01:00 |
|
Ruben Groenewoud
|
561ab703de
|
[New Rule] Uncommon Destination Port Connection by Web Server (#4515)
|
2025-03-06 22:01:33 +05:30 |
|
Ruben Groenewoud
|
fe0a9f4935
|
[New/Tuning] Docker Socket Enumeration (#4510)
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2025-03-06 17:07:10 +01:00 |
|
Ruben Groenewoud
|
8dfa5da3bf
|
[New Rules] Potential Port/Subnet Scanning Activity from Compromised Host (#4509)
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2025-03-06 16:57:33 +01:00 |
|
Ruben Groenewoud
|
fe06843636
|
[New Rule] Unusual Process Spawned from Web Server Parent (#4513)
|
2025-03-06 16:46:12 +01:00 |
|
Ruben Groenewoud
|
7ce6aaf566
|
[New Rule] Unusual Command Execution from Web Server Parent (#4512)
* [New Rule] Unusual Command Execution from Web Server Parent
* ++
|
2025-03-06 16:25:38 +01:00 |
|
Ruben Groenewoud
|
b9e8115c2f
|
[New Rule] Python Site or User Customize File Creation (#4500)
* [New Rule] Python Site or User Customize File Creation
* Update persistence_site_and_user_customize_file_creation.toml
* Update persistence_site_and_user_customize_file_creation.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2025-03-03 15:30:33 +01:00 |
|
Ruben Groenewoud
|
d948279af6
|
[New Rule] Python Path File (pth) Creation (#4499)
* [New Rule] Python Path File (pth) Creation
* ++
* Update persistence_pth_file_creation.toml
* Update persistence_pth_file_creation.toml
* Update persistence_pth_file_creation.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
|
2025-03-03 15:20:00 +01:00 |
|