Commit Graph

2741 Commits

Author SHA1 Message Date
Terrance DeJesus 557c6bbef9 [New Rule] Adding Coverage for Microsoft Entra ID SharePoint Access for User Principal via Auth Broker (#4695)
* new rule 'Microsoft Entra ID SharePoint Access for User Principal via Auth Broker'

* updated severity

* added new terms note

(cherry picked from commit 58d03d4043)
2025-05-05 20:49:59 +00:00
shashank-elastic fd7e14bcd7 Refresh ecs, beats, integration manifests & schemas (#4699)
(cherry picked from commit e4856d3c2c)
2025-05-05 17:41:00 +00:00
Ruben Groenewoud e38f15bcf6 [New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658)
(cherry picked from commit 18e1103c51)
2025-05-05 08:03:40 +00:00
shashank-elastic 8f880c00a8 Deprecate Experimental ML command (#4669)
(cherry picked from commit b3adc6d3ea)
2025-05-02 15:36:09 +00:00
Samirbous 6be77cdf9d [New] Microsoft 365 OAuth Redirect to Device Registration for User (#4694)
* [New] Microsoft 365 OAuth Redirect to Device Registration for User Principal

https://github.com/elastic/ia-trade-team/issues/590

* Update non-ecs-schema.json

* Update pyproject.toml

* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml

* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml

* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml

* fixed investigation guide formatting; fixed unit test failure

* updated patch version

---------

Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit dddc2a7bb9)
2025-05-02 07:40:22 +00:00
Terrance DeJesus 208143f764 [New Rule] Adding Coverage for Microsoft Entra ID Protection Anonymized IP Risk Detection (#4689)
* Adding new rule 'Microsoft Entra ID Protection Anonymized IP Risk Detection'

* updating description

* adding index

* updating mitre tactic mapping

* updating file name

(cherry picked from commit ce66f52aad)
2025-05-02 03:08:09 +00:00
Terrance DeJesus 7b8fbfbc5c [New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client (#4642)
* new rules for MSFT Oauth phishing in Azure, Entra and Microsoft 365

* changed m365 file name

* fixed duplicate tactics

* updaing non-ecs for graph activity logs

* updating rules; investigation guides; formatting, linting errors

(cherry picked from commit bae7835f6a)
2025-05-02 02:42:59 +00:00
Terrance DeJesus fe56029136 [New Rule] Adding Coverage for AWS S3 Static Site JavaScript File Uploaded (#4617)
* new rule 'AWS S3 Static Site JavaScript File Uploaded'

* adjusting name

* updated keep command

---------

Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>

(cherry picked from commit ff2ecad573)
2025-04-30 20:29:03 +00:00
Sergey Polzunov 8ab7d609b4 fix: Fixing leftover references to sha256 method (#4690)
* Fixing missed old method name usage

* Patch version bump

(cherry picked from commit ba959f2ceb)
2025-04-30 18:38:17 +00:00
github-actions[bot] 7b6be2ceff Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4679)
(cherry picked from commit fc1e6145cc)
integration-v8.18.3
2025-04-30 12:46:52 +00:00
Colson Wilhoit a3d364a02c [Tuning] MacOS DR Tuning PR (#4546)
* [Tuning] MacOS DR Tuning PR

* tunings

* tuning

* Update rules/macos/execution_scripting_osascript_exec_followed_by_netcon.toml

* Update rules/macos/execution_installer_package_spawned_network_event.toml

* Update rules/macos/execution_script_via_automator_workflows.toml

* Update rules/macos/credential_access_systemkey_dumping.toml

* Update rules/macos/credential_access_mitm_localhost_webproxy.toml

* Update rules/macos/credential_access_promt_for_pwd_via_osascript.toml

* Update rules/macos/defense_evasion_apple_softupdates_modification.toml

* Update rules/macos/lateral_movement_credential_access_kerberos_bifrostconsole.toml

* Update rules/macos/lateral_movement_remote_ssh_login_enabled.toml

* Update rules/macos/persistence_finder_sync_plugin_pluginkit.toml

* fix

---------

Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
2025-04-29 11:49:41 -04:00
Sergey Polzunov 7b152b9437 Bringing back "fix: Cleaning up the hashable content for the rule" (#4621) (#4668)
(cherry picked from commit d72cb92d59)
2025-04-28 16:34:25 +00:00
shashank-elastic 571e5248d9 Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4665)
(cherry picked from commit 97e6d8b706)
integration-v8.18.2
2025-04-25 15:09:39 +00:00
Terrance DeJesus 66701ff663 [New Rule] Adding Coverage for AWS IAM or STS API Calls via Temporary Session Tokens (#4628)
* adding new rule 'AWS IAM or STS API Calls via Temporary Session Tokens'

* updated name and query logic

* updated query logic

* changed rule to new terms

* fixed logic

* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml

* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml

* updated investigation guide; scoped to IAM only; updated naming

* updating file name

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit f02ccfef64)
2025-04-24 19:44:16 +00:00
Sergey Polzunov 3a8f5d6b69 Version bump (#4655)
(cherry picked from commit 191396e5e8)
2025-04-24 17:25:48 +00:00
Sergey Polzunov bc8377b260 Revert "fix: Cleaning up the hashable content for the rule (#4621)" (#4654)
This reverts commit 80c4f7eacc.

(cherry picked from commit b7a324b2e8)
2025-04-24 17:09:46 +00:00
Colson Wilhoit 04a81f791f [Tuning] Update DPRK ByBit Hunting Queries (#4645)
* fix

* markdown generate

* adding missing streamlit hunting query

---------

Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

(cherry picked from commit 84966f02a1)
2025-04-24 13:02:38 +00:00
Sergey Polzunov 739b2d1088 fix: Cleaning up the hashable content for the rule (#4621)
(cherry picked from commit 80c4f7eacc)
2025-04-24 09:07:55 +00:00
Isai 0e3e5ed269 [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648)
(cherry picked from commit b429be2bda)
2025-04-24 04:53:19 +00:00
github-actions[bot] 48e9b20967 Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4649)
(cherry picked from commit 70062c3991)
2025-04-24 01:46:57 +00:00
Jonhnathan 67e807fb18 [Rule Tuning] User Added to Privileged Group in Active Directory (#4646)
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>

(cherry picked from commit b9ed05562d)
2025-04-24 00:46:59 +00:00
Jonhnathan 176b1d5e9b [Rule Tuning] Replace legacy winlog.api usage (#4647)
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>

(cherry picked from commit e8e76972f5)
2025-04-24 00:26:50 +00:00
shashank-elastic 85745b598d Add 8.18 and 9.0 beats schemas (#4641)
(cherry picked from commit 54fadc8e2e)
2025-04-24 00:11:20 +00:00
Terrance DeJesus 38d7c4eb5e [New Hunt] New Hunting Queries for DPRK ByBit (#4644)
* new hunting queries for macOS DPRK

* added docker hunting queries

(cherry picked from commit bbfc026c95)
2025-04-23 20:45:50 +00:00
Samirbous b51d37eac5 [New] Suspicious Azure Sign-in via Visual Studio Code (#4639)
* Create initial_access_entra_login_visual_code_phish.toml

* Update non-ecs-schema.json

* Update initial_access_entra_susp_visual_code_signin.toml

* Update pyproject.toml

* Update initial_access_entra_susp_visual_code_signin.toml

* Update non-ecs-schema.json

(cherry picked from commit ea31143b83)
2025-04-23 13:10:57 +00:00
Samirbous 3b79b87b0d [New] RemoteMonologue Attack rules (#4604)
* [New] RemoteMonologue Attack rules

https://www.ibm.com/think/x-force/remotemonologue-weaponizing-dcom-ntlm-authentication-coercions#1
    https://github.com/xforcered/RemoteMonologue

* Update rules/windows/defense_evasion_ntlm_downgrade.toml

Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>

* Update defense_evasion_ntlm_downgrade.toml

* Update rules/windows/defense_evasion_ntlm_downgrade.toml

* Update rules/windows/defense_evasion_ntlm_downgrade.toml

---------

Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>

(cherry picked from commit f8e91be329)
2025-04-22 18:31:46 +00:00
Jonhnathan 49894fe7b2 [New Rule] Potential Malicious PowerShell Based on Alert Correlation (#4635)
* [New Rule] Potential Malicious PowerShell Based on Alert Correlation

* Update execution_posh_malicious_script_agg.toml

(cherry picked from commit 1bab74179e)
2025-04-22 16:40:27 +00:00
Colson Wilhoit 957dcfb6ca [Deprecate] LaunchDaemon Creation or Modification and Immediate Loading (#4547)
(cherry picked from commit c80319d462)
2025-04-22 15:57:47 +00:00
Jonhnathan d9cead96bb [New Rule] Potential PowerShell Obfuscation via String Reordering (#4595)
* [New Rule] Potential PowerShell Obfuscation via String Reordering

* Update defense_evasion_posh_obfuscation_string_format.toml

* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml

* Update defense_evasion_posh_obfuscation_string_format.toml

* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml

* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml

(cherry picked from commit 8361cfd205)
2025-04-22 15:31:14 +00:00
Jonhnathan 987c8ecf12 [New Rule] Threat Intel Email Indicator Match (#4598)
* [New Rule] Threat Intel Email Indicator Match

* Update threat_intel_indicator_match_email.toml

* Update pyproject.toml

* Adds IG

* Update rules/threat_intel/threat_intel_indicator_match_email.toml

* Update rules/threat_intel/threat_intel_indicator_match_email.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/threat_intel/threat_intel_indicator_match_email.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit 364d9dd3bc)
2025-04-22 15:20:05 +00:00
Jonhnathan b293ced1e1 [Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4627)
(cherry picked from commit a495b4b9b2)
2025-04-22 15:03:30 +00:00
Jonhnathan a92a21d668 [New Rule] Dynamic IEX Reconstruction via Method String Access (#4634)
(cherry picked from commit a9f99137f3)
2025-04-22 14:51:18 +00:00
Terrance DeJesus d2008a36e3 [New Rule] Adding Coverage for AWS CLI with Kali Linux Fingerprint Identified (#4625)
* adding new rule 'AWS CLI with Kali Linux Fingerprint Identified'

* updating rule logic

* updating mitre mapping

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>

(cherry picked from commit c58d59eeb7)
2025-04-21 16:11:13 +00:00
Terrance DeJesus de507603ac [New Rule] Adding Coverage for AWS IAM Virtual MFA Device Registration (#4626)
* adding new rule 'AWS IAM Virtual MFA Device Registration Attempt with Session Token'

* updating rule

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>

(cherry picked from commit 94237798a5)
2025-04-21 15:06:35 +00:00
Terrance DeJesus e276d8ef91 [New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses (#4624)
* adding new rule 'AWS STS Temporary IAM Session Token Used from Multiple Addresses'

* updating rule assets

* updating mitre mapping

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>

(cherry picked from commit 96c2d0ca85)
2025-04-17 20:10:48 +00:00
Eric Forte 3e9d945a4f [Bug] Update Schema Prompt to include new_terms_fields (#4567)
* Update Schema Prompt to include new_terms_fields

* Version Bump

* Ensure list of strings

* Update utils to support comma deliminated strings

* Also remove excess quotes

* Bump patch version

* Remove Union

* bump version

(cherry picked from commit 62feac3348)
2025-04-17 14:50:19 +00:00
Frederik Berg ec0f4123ca [Enhancement] Add flag to export rules via KQL search on name (#4594)
* Add flag to export rules via KQL search on name

* Add KQL to help text

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

* version patch bump

* flake8 trimming

* pyproject bump

* Bump version

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co>

(cherry picked from commit 6cb238bedb)
2025-04-16 22:44:53 +00:00
Frederik Berg 9c831fb217 Feature exclude tactic name (#4593)
* Added new cli flag to exclude tactic name in rule file name

* added a shortcut for the flag and adjusted CLI readme

* Add no tactic flag also to import to prevent warnings

* Added info about unit test

* version bump

* Added no_tactic_filename as config option + fixed linting

* pyproject version bump

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 9b682b752c)
2025-04-16 20:06:57 +00:00
Eric Forte 3306865c0f [FR] Add Support for Local Dates Flag (#4582)
* Add support for local dates flag

* Use two variables

* Add support for import-rules-to-repo

* Revert arg formatting

* Update comment

* Pass Rule Path as Path Object

* Update to rule loader function

* Streamline metadata function

* Also support dictionaries

* Bump patch version

* Reduce complexity

* Add if path exists check

* Fix version bump

(cherry picked from commit 033c82858c)
2025-04-16 19:45:32 +00:00
Terrance DeJesus 80a3f7f405 [Rule Tuning] Tuning Azure Service Principal Credentials Added (#4570)
* tuning 'Azure Service Principal Credentials Added'

* updated patch version

* added investigation guide

* updating patch version

* updating patch version

(cherry picked from commit ba16e27edb)
2025-04-16 18:02:48 +00:00
Terrance DeJesus 2bb46f4c7b [Rule Tuning] Adjusting Microsoft Entra ID Rare Authentication Requirement for Principal User (#4562)
* tuning 'Microsoft Entra ID Rare Authentication Requirement for Principal User'

* updated MITRE ATT&CK mappings

* updated index target

* updated patch version

* updating patch version

* bumping patch version

* updating patch version

(cherry picked from commit 1a6669e5a6)
2025-04-16 16:26:15 +00:00
Jonhnathan 9f7dd9891b [Rule Tuning] Suspicious WMI Event Subscription Created (#4618)
* [Rule Tuning] Suspicious Execution via Scheduled Task

* [Rule Tuning] Suspicious WMI Event Subscription Created

(cherry picked from commit e11fe78846)
2025-04-16 13:10:23 +00:00
Jonhnathan e0f689f18e [Rule Tuning] SSH Authorized Keys File Deletion (#4591)
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 3eed0f5b6a)
2025-04-15 15:20:58 +00:00
Eric Forte 58bbc2d533 [FR] Add Kibana Action Connector Error to Exception List Workaround (#4583)
* Add error catch for workaround

* Switch to set for efficiency

* Patch version bump

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit ea7de8230c)
2025-04-15 13:23:27 +00:00
Eric Forte dd7240343b [FR] Update Detection Rules MITRE Workflow to SHA Pin (#4581)
* Update to pinned hash

* version bump

(cherry picked from commit 108b64f0c2)
2025-04-15 13:08:17 +00:00
shashank-elastic b59a296ecc Remove Task List reference (#4605)
(cherry picked from commit 595d204fe6)
2025-04-15 03:57:35 +00:00
Ruben Groenewoud 50758935f6 [D4C Conversion] Converting Compatible D4C Rules to DR (#4532)
* [D4C Conversion] Converting Compatible D4C Rules to DR

* added host.os.type

* Rename

* Update rules/linux/execution_container_management_binary_launched_inside_container.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 3b1f780435)
2025-04-10 12:31:24 +00:00
Ruben Groenewoud 2a07268bdb [FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529)
* [FN Tuning] Shared Object Created or Changed by Previously Unknown Process

* Update process exclusions in TOML file

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 05c9f6bbdb)
2025-04-08 16:23:58 +00:00
github-actions[bot] deefc8830c Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4601)
(cherry picked from commit fbddc2e659)
integration-v8.18.1
2025-04-08 13:00:35 +00:00
Jonhnathan 0725866926 [Rule Tuning] Suspicious Execution via Scheduled Task (#4599)
(cherry picked from commit a5d9d6400a)
2025-04-07 17:33:36 +00:00