Terrance DeJesus
557c6bbef9
[New Rule] Adding Coverage for Microsoft Entra ID SharePoint Access for User Principal via Auth Broker ( #4695 )
...
* new rule 'Microsoft Entra ID SharePoint Access for User Principal via Auth Broker'
* updated severity
* added new terms note
(cherry picked from commit 58d03d4043 )
2025-05-05 20:49:59 +00:00
shashank-elastic
fd7e14bcd7
Refresh ecs, beats, integration manifests & schemas ( #4699 )
...
(cherry picked from commit e4856d3c2c )
2025-05-05 17:41:00 +00:00
Ruben Groenewoud
e38f15bcf6
[New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option ( #4658 )
...
(cherry picked from commit 18e1103c51 )
2025-05-05 08:03:40 +00:00
shashank-elastic
8f880c00a8
Deprecate Experimental ML command ( #4669 )
...
(cherry picked from commit b3adc6d3ea )
2025-05-02 15:36:09 +00:00
Samirbous
6be77cdf9d
[New] Microsoft 365 OAuth Redirect to Device Registration for User ( #4694 )
...
* [New] Microsoft 365 OAuth Redirect to Device Registration for User Principal
https://github.com/elastic/ia-trade-team/issues/590
* Update non-ecs-schema.json
* Update pyproject.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* fixed investigation guide formatting; fixed unit test failure
* updated patch version
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
(cherry picked from commit dddc2a7bb9 )
2025-05-02 07:40:22 +00:00
Terrance DeJesus
208143f764
[New Rule] Adding Coverage for Microsoft Entra ID Protection Anonymized IP Risk Detection ( #4689 )
...
* Adding new rule 'Microsoft Entra ID Protection Anonymized IP Risk Detection'
* updating description
* adding index
* updating mitre tactic mapping
* updating file name
(cherry picked from commit ce66f52aad )
2025-05-02 03:08:09 +00:00
Terrance DeJesus
7b8fbfbc5c
[New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client ( #4642 )
...
* new rules for MSFT Oauth phishing in Azure, Entra and Microsoft 365
* changed m365 file name
* fixed duplicate tactics
* updaing non-ecs for graph activity logs
* updating rules; investigation guides; formatting, linting errors
(cherry picked from commit bae7835f6a )
2025-05-02 02:42:59 +00:00
Terrance DeJesus
fe56029136
[New Rule] Adding Coverage for AWS S3 Static Site JavaScript File Uploaded ( #4617 )
...
* new rule 'AWS S3 Static Site JavaScript File Uploaded'
* adjusting name
* updated keep command
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit ff2ecad573 )
2025-04-30 20:29:03 +00:00
Sergey Polzunov
8ab7d609b4
fix: Fixing leftover references to sha256 method ( #4690 )
...
* Fixing missed old method name usage
* Patch version bump
(cherry picked from commit ba959f2ceb )
2025-04-30 18:38:17 +00:00
github-actions[bot]
7b6be2ceff
Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 ( #4679 )
...
(cherry picked from commit fc1e6145cc )
integration-v8.18.3
2025-04-30 12:46:52 +00:00
Colson Wilhoit
a3d364a02c
[Tuning] MacOS DR Tuning PR ( #4546 )
...
* [Tuning] MacOS DR Tuning PR
* tunings
* tuning
* Update rules/macos/execution_scripting_osascript_exec_followed_by_netcon.toml
* Update rules/macos/execution_installer_package_spawned_network_event.toml
* Update rules/macos/execution_script_via_automator_workflows.toml
* Update rules/macos/credential_access_systemkey_dumping.toml
* Update rules/macos/credential_access_mitm_localhost_webproxy.toml
* Update rules/macos/credential_access_promt_for_pwd_via_osascript.toml
* Update rules/macos/defense_evasion_apple_softupdates_modification.toml
* Update rules/macos/lateral_movement_credential_access_kerberos_bifrostconsole.toml
* Update rules/macos/lateral_movement_remote_ssh_login_enabled.toml
* Update rules/macos/persistence_finder_sync_plugin_pluginkit.toml
* fix
---------
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
2025-04-29 11:49:41 -04:00
Sergey Polzunov
7b152b9437
Bringing back "fix: Cleaning up the hashable content for the rule" ( #4621 ) ( #4668 )
...
(cherry picked from commit d72cb92d59 )
2025-04-28 16:34:25 +00:00
shashank-elastic
571e5248d9
Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 ( #4665 )
...
(cherry picked from commit 97e6d8b706 )
integration-v8.18.2
2025-04-25 15:09:39 +00:00
Terrance DeJesus
66701ff663
[New Rule] Adding Coverage for AWS IAM or STS API Calls via Temporary Session Tokens ( #4628 )
...
* adding new rule 'AWS IAM or STS API Calls via Temporary Session Tokens'
* updated name and query logic
* updated query logic
* changed rule to new terms
* fixed logic
* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml
* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml
* updated investigation guide; scoped to IAM only; updated naming
* updating file name
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit f02ccfef64 )
2025-04-24 19:44:16 +00:00
Sergey Polzunov
3a8f5d6b69
Version bump ( #4655 )
...
(cherry picked from commit 191396e5e8 )
2025-04-24 17:25:48 +00:00
Sergey Polzunov
bc8377b260
Revert "fix: Cleaning up the hashable content for the rule ( #4621 )" ( #4654 )
...
This reverts commit 80c4f7eacc .
(cherry picked from commit b7a324b2e8 )
2025-04-24 17:09:46 +00:00
Colson Wilhoit
04a81f791f
[Tuning] Update DPRK ByBit Hunting Queries ( #4645 )
...
* fix
* markdown generate
* adding missing streamlit hunting query
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
(cherry picked from commit 84966f02a1 )
2025-04-24 13:02:38 +00:00
Sergey Polzunov
739b2d1088
fix: Cleaning up the hashable content for the rule ( #4621 )
...
(cherry picked from commit 80c4f7eacc )
2025-04-24 09:07:55 +00:00
Isai
0e3e5ed269
[Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation ( #4648 )
...
(cherry picked from commit b429be2bda )
2025-04-24 04:53:19 +00:00
github-actions[bot]
48e9b20967
Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md ( #4649 )
...
(cherry picked from commit 70062c3991 )
2025-04-24 01:46:57 +00:00
Jonhnathan
67e807fb18
[Rule Tuning] User Added to Privileged Group in Active Directory ( #4646 )
...
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
(cherry picked from commit b9ed05562d )
2025-04-24 00:46:59 +00:00
Jonhnathan
176b1d5e9b
[Rule Tuning] Replace legacy winlog.api usage ( #4647 )
...
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
(cherry picked from commit e8e76972f5 )
2025-04-24 00:26:50 +00:00
shashank-elastic
85745b598d
Add 8.18 and 9.0 beats schemas ( #4641 )
...
(cherry picked from commit 54fadc8e2e )
2025-04-24 00:11:20 +00:00
Terrance DeJesus
38d7c4eb5e
[New Hunt] New Hunting Queries for DPRK ByBit ( #4644 )
...
* new hunting queries for macOS DPRK
* added docker hunting queries
(cherry picked from commit bbfc026c95 )
2025-04-23 20:45:50 +00:00
Samirbous
b51d37eac5
[New] Suspicious Azure Sign-in via Visual Studio Code ( #4639 )
...
* Create initial_access_entra_login_visual_code_phish.toml
* Update non-ecs-schema.json
* Update initial_access_entra_susp_visual_code_signin.toml
* Update pyproject.toml
* Update initial_access_entra_susp_visual_code_signin.toml
* Update non-ecs-schema.json
(cherry picked from commit ea31143b83 )
2025-04-23 13:10:57 +00:00
Samirbous
3b79b87b0d
[New] RemoteMonologue Attack rules ( #4604 )
...
* [New] RemoteMonologue Attack rules
https://www.ibm.com/think/x-force/remotemonologue-weaponizing-dcom-ntlm-authentication-coercions#1
https://github.com/xforcered/RemoteMonologue
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
* Update defense_evasion_ntlm_downgrade.toml
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit f8e91be329 )
2025-04-22 18:31:46 +00:00
Jonhnathan
49894fe7b2
[New Rule] Potential Malicious PowerShell Based on Alert Correlation ( #4635 )
...
* [New Rule] Potential Malicious PowerShell Based on Alert Correlation
* Update execution_posh_malicious_script_agg.toml
(cherry picked from commit 1bab74179e )
2025-04-22 16:40:27 +00:00
Colson Wilhoit
957dcfb6ca
[Deprecate] LaunchDaemon Creation or Modification and Immediate Loading ( #4547 )
...
(cherry picked from commit c80319d462 )
2025-04-22 15:57:47 +00:00
Jonhnathan
d9cead96bb
[New Rule] Potential PowerShell Obfuscation via String Reordering ( #4595 )
...
* [New Rule] Potential PowerShell Obfuscation via String Reordering
* Update defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
* Update defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
(cherry picked from commit 8361cfd205 )
2025-04-22 15:31:14 +00:00
Jonhnathan
987c8ecf12
[New Rule] Threat Intel Email Indicator Match ( #4598 )
...
* [New Rule] Threat Intel Email Indicator Match
* Update threat_intel_indicator_match_email.toml
* Update pyproject.toml
* Adds IG
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
(cherry picked from commit 364d9dd3bc )
2025-04-22 15:20:05 +00:00
Jonhnathan
b293ced1e1
[Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs ( #4627 )
...
(cherry picked from commit a495b4b9b2 )
2025-04-22 15:03:30 +00:00
Jonhnathan
a92a21d668
[New Rule] Dynamic IEX Reconstruction via Method String Access ( #4634 )
...
(cherry picked from commit a9f99137f3 )
2025-04-22 14:51:18 +00:00
Terrance DeJesus
d2008a36e3
[New Rule] Adding Coverage for AWS CLI with Kali Linux Fingerprint Identified ( #4625 )
...
* adding new rule 'AWS CLI with Kali Linux Fingerprint Identified'
* updating rule logic
* updating mitre mapping
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit c58d59eeb7 )
2025-04-21 16:11:13 +00:00
Terrance DeJesus
de507603ac
[New Rule] Adding Coverage for AWS IAM Virtual MFA Device Registration ( #4626 )
...
* adding new rule 'AWS IAM Virtual MFA Device Registration Attempt with Session Token'
* updating rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit 94237798a5 )
2025-04-21 15:06:35 +00:00
Terrance DeJesus
e276d8ef91
[New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses ( #4624 )
...
* adding new rule 'AWS STS Temporary IAM Session Token Used from Multiple Addresses'
* updating rule assets
* updating mitre mapping
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit 96c2d0ca85 )
2025-04-17 20:10:48 +00:00
Eric Forte
3e9d945a4f
[Bug] Update Schema Prompt to include new_terms_fields ( #4567 )
...
* Update Schema Prompt to include new_terms_fields
* Version Bump
* Ensure list of strings
* Update utils to support comma deliminated strings
* Also remove excess quotes
* Bump patch version
* Remove Union
* bump version
(cherry picked from commit 62feac3348 )
2025-04-17 14:50:19 +00:00
Frederik Berg
ec0f4123ca
[Enhancement] Add flag to export rules via KQL search on name ( #4594 )
...
* Add flag to export rules via KQL search on name
* Add KQL to help text
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
* version patch bump
* flake8 trimming
* pyproject bump
* Bump version
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co >
(cherry picked from commit 6cb238bedb )
2025-04-16 22:44:53 +00:00
Frederik Berg
9c831fb217
Feature exclude tactic name ( #4593 )
...
* Added new cli flag to exclude tactic name in rule file name
* added a shortcut for the flag and adjusted CLI readme
* Add no tactic flag also to import to prevent warnings
* Added info about unit test
* version bump
* Added no_tactic_filename as config option + fixed linting
* pyproject version bump
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
(cherry picked from commit 9b682b752c )
2025-04-16 20:06:57 +00:00
Eric Forte
3306865c0f
[FR] Add Support for Local Dates Flag ( #4582 )
...
* Add support for local dates flag
* Use two variables
* Add support for import-rules-to-repo
* Revert arg formatting
* Update comment
* Pass Rule Path as Path Object
* Update to rule loader function
* Streamline metadata function
* Also support dictionaries
* Bump patch version
* Reduce complexity
* Add if path exists check
* Fix version bump
(cherry picked from commit 033c82858c )
2025-04-16 19:45:32 +00:00
Terrance DeJesus
80a3f7f405
[Rule Tuning] Tuning Azure Service Principal Credentials Added ( #4570 )
...
* tuning 'Azure Service Principal Credentials Added'
* updated patch version
* added investigation guide
* updating patch version
* updating patch version
(cherry picked from commit ba16e27edb )
2025-04-16 18:02:48 +00:00
Terrance DeJesus
2bb46f4c7b
[Rule Tuning] Adjusting Microsoft Entra ID Rare Authentication Requirement for Principal User ( #4562 )
...
* tuning 'Microsoft Entra ID Rare Authentication Requirement for Principal User'
* updated MITRE ATT&CK mappings
* updated index target
* updated patch version
* updating patch version
* bumping patch version
* updating patch version
(cherry picked from commit 1a6669e5a6 )
2025-04-16 16:26:15 +00:00
Jonhnathan
9f7dd9891b
[Rule Tuning] Suspicious WMI Event Subscription Created ( #4618 )
...
* [Rule Tuning] Suspicious Execution via Scheduled Task
* [Rule Tuning] Suspicious WMI Event Subscription Created
(cherry picked from commit e11fe78846 )
2025-04-16 13:10:23 +00:00
Jonhnathan
e0f689f18e
[Rule Tuning] SSH Authorized Keys File Deletion ( #4591 )
...
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 3eed0f5b6a )
2025-04-15 15:20:58 +00:00
Eric Forte
58bbc2d533
[FR] Add Kibana Action Connector Error to Exception List Workaround ( #4583 )
...
* Add error catch for workaround
* Switch to set for efficiency
* Patch version bump
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit ea7de8230c )
2025-04-15 13:23:27 +00:00
Eric Forte
dd7240343b
[FR] Update Detection Rules MITRE Workflow to SHA Pin ( #4581 )
...
* Update to pinned hash
* version bump
(cherry picked from commit 108b64f0c2 )
2025-04-15 13:08:17 +00:00
shashank-elastic
b59a296ecc
Remove Task List reference ( #4605 )
...
(cherry picked from commit 595d204fe6 )
2025-04-15 03:57:35 +00:00
Ruben Groenewoud
50758935f6
[D4C Conversion] Converting Compatible D4C Rules to DR ( #4532 )
...
* [D4C Conversion] Converting Compatible D4C Rules to DR
* added host.os.type
* Rename
* Update rules/linux/execution_container_management_binary_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 3b1f780435 )
2025-04-10 12:31:24 +00:00
Ruben Groenewoud
2a07268bdb
[FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… ( #4529 )
...
* [FN Tuning] Shared Object Created or Changed by Previously Unknown Process
* Update process exclusions in TOML file
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
(cherry picked from commit 05c9f6bbdb )
2025-04-08 16:23:58 +00:00
github-actions[bot]
deefc8830c
Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 ( #4601 )
...
(cherry picked from commit fbddc2e659 )
integration-v8.18.1
2025-04-08 13:00:35 +00:00
Jonhnathan
0725866926
[Rule Tuning] Suspicious Execution via Scheduled Task ( #4599 )
...
(cherry picked from commit a5d9d6400a )
2025-04-07 17:33:36 +00:00