Terrance DeJesus
557c6bbef9
[New Rule] Adding Coverage for Microsoft Entra ID SharePoint Access for User Principal via Auth Broker ( #4695 )
...
* new rule 'Microsoft Entra ID SharePoint Access for User Principal via Auth Broker'
* updated severity
* added new terms note
(cherry picked from commit 58d03d4043 )
2025-05-05 20:49:59 +00:00
shashank-elastic
fd7e14bcd7
Refresh ecs, beats, integration manifests & schemas ( #4699 )
...
(cherry picked from commit e4856d3c2c )
2025-05-05 17:41:00 +00:00
Ruben Groenewoud
e38f15bcf6
[New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option ( #4658 )
...
(cherry picked from commit 18e1103c51 )
2025-05-05 08:03:40 +00:00
Samirbous
6be77cdf9d
[New] Microsoft 365 OAuth Redirect to Device Registration for User ( #4694 )
...
* [New] Microsoft 365 OAuth Redirect to Device Registration for User Principal
https://github.com/elastic/ia-trade-team/issues/590
* Update non-ecs-schema.json
* Update pyproject.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* Update credential_access_antra_id_device_reg_via_oauth_redirection.toml
* fixed investigation guide formatting; fixed unit test failure
* updated patch version
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
(cherry picked from commit dddc2a7bb9 )
2025-05-02 07:40:22 +00:00
Terrance DeJesus
208143f764
[New Rule] Adding Coverage for Microsoft Entra ID Protection Anonymized IP Risk Detection ( #4689 )
...
* Adding new rule 'Microsoft Entra ID Protection Anonymized IP Risk Detection'
* updating description
* adding index
* updating mitre tactic mapping
* updating file name
(cherry picked from commit ce66f52aad )
2025-05-02 03:08:09 +00:00
Terrance DeJesus
7b8fbfbc5c
[New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client ( #4642 )
...
* new rules for MSFT Oauth phishing in Azure, Entra and Microsoft 365
* changed m365 file name
* fixed duplicate tactics
* updaing non-ecs for graph activity logs
* updating rules; investigation guides; formatting, linting errors
(cherry picked from commit bae7835f6a )
2025-05-02 02:42:59 +00:00
Terrance DeJesus
fe56029136
[New Rule] Adding Coverage for AWS S3 Static Site JavaScript File Uploaded ( #4617 )
...
* new rule 'AWS S3 Static Site JavaScript File Uploaded'
* adjusting name
* updated keep command
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit ff2ecad573 )
2025-04-30 20:29:03 +00:00
Colson Wilhoit
a3d364a02c
[Tuning] MacOS DR Tuning PR ( #4546 )
...
* [Tuning] MacOS DR Tuning PR
* tunings
* tuning
* Update rules/macos/execution_scripting_osascript_exec_followed_by_netcon.toml
* Update rules/macos/execution_installer_package_spawned_network_event.toml
* Update rules/macos/execution_script_via_automator_workflows.toml
* Update rules/macos/credential_access_systemkey_dumping.toml
* Update rules/macos/credential_access_mitm_localhost_webproxy.toml
* Update rules/macos/credential_access_promt_for_pwd_via_osascript.toml
* Update rules/macos/defense_evasion_apple_softupdates_modification.toml
* Update rules/macos/lateral_movement_credential_access_kerberos_bifrostconsole.toml
* Update rules/macos/lateral_movement_remote_ssh_login_enabled.toml
* Update rules/macos/persistence_finder_sync_plugin_pluginkit.toml
* fix
---------
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
2025-04-29 11:49:41 -04:00
Terrance DeJesus
66701ff663
[New Rule] Adding Coverage for AWS IAM or STS API Calls via Temporary Session Tokens ( #4628 )
...
* adding new rule 'AWS IAM or STS API Calls via Temporary Session Tokens'
* updated name and query logic
* updated query logic
* changed rule to new terms
* fixed logic
* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml
* Update rules/integrations/aws/persistence_iam_sts_api_calls_via_user_session_token.toml
* updated investigation guide; scoped to IAM only; updated naming
* updating file name
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
(cherry picked from commit f02ccfef64 )
2025-04-24 19:44:16 +00:00
Isai
0e3e5ed269
[Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation ( #4648 )
...
(cherry picked from commit b429be2bda )
2025-04-24 04:53:19 +00:00
Jonhnathan
67e807fb18
[Rule Tuning] User Added to Privileged Group in Active Directory ( #4646 )
...
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
(cherry picked from commit b9ed05562d )
2025-04-24 00:46:59 +00:00
Jonhnathan
176b1d5e9b
[Rule Tuning] Replace legacy winlog.api usage ( #4647 )
...
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
(cherry picked from commit e8e76972f5 )
2025-04-24 00:26:50 +00:00
Samirbous
b51d37eac5
[New] Suspicious Azure Sign-in via Visual Studio Code ( #4639 )
...
* Create initial_access_entra_login_visual_code_phish.toml
* Update non-ecs-schema.json
* Update initial_access_entra_susp_visual_code_signin.toml
* Update pyproject.toml
* Update initial_access_entra_susp_visual_code_signin.toml
* Update non-ecs-schema.json
(cherry picked from commit ea31143b83 )
2025-04-23 13:10:57 +00:00
Samirbous
3b79b87b0d
[New] RemoteMonologue Attack rules ( #4604 )
...
* [New] RemoteMonologue Attack rules
https://www.ibm.com/think/x-force/remotemonologue-weaponizing-dcom-ntlm-authentication-coercions#1
https://github.com/xforcered/RemoteMonologue
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
* Update defense_evasion_ntlm_downgrade.toml
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
* Update rules/windows/defense_evasion_ntlm_downgrade.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit f8e91be329 )
2025-04-22 18:31:46 +00:00
Jonhnathan
49894fe7b2
[New Rule] Potential Malicious PowerShell Based on Alert Correlation ( #4635 )
...
* [New Rule] Potential Malicious PowerShell Based on Alert Correlation
* Update execution_posh_malicious_script_agg.toml
(cherry picked from commit 1bab74179e )
2025-04-22 16:40:27 +00:00
Colson Wilhoit
957dcfb6ca
[Deprecate] LaunchDaemon Creation or Modification and Immediate Loading ( #4547 )
...
(cherry picked from commit c80319d462 )
2025-04-22 15:57:47 +00:00
Jonhnathan
d9cead96bb
[New Rule] Potential PowerShell Obfuscation via String Reordering ( #4595 )
...
* [New Rule] Potential PowerShell Obfuscation via String Reordering
* Update defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
* Update defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
* Update rules/windows/defense_evasion_posh_obfuscation_string_format.toml
(cherry picked from commit 8361cfd205 )
2025-04-22 15:31:14 +00:00
Jonhnathan
987c8ecf12
[New Rule] Threat Intel Email Indicator Match ( #4598 )
...
* [New Rule] Threat Intel Email Indicator Match
* Update threat_intel_indicator_match_email.toml
* Update pyproject.toml
* Adds IG
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/threat_intel/threat_intel_indicator_match_email.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
(cherry picked from commit 364d9dd3bc )
2025-04-22 15:20:05 +00:00
Jonhnathan
b293ced1e1
[Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs ( #4627 )
...
(cherry picked from commit a495b4b9b2 )
2025-04-22 15:03:30 +00:00
Jonhnathan
a92a21d668
[New Rule] Dynamic IEX Reconstruction via Method String Access ( #4634 )
...
(cherry picked from commit a9f99137f3 )
2025-04-22 14:51:18 +00:00
Terrance DeJesus
d2008a36e3
[New Rule] Adding Coverage for AWS CLI with Kali Linux Fingerprint Identified ( #4625 )
...
* adding new rule 'AWS CLI with Kali Linux Fingerprint Identified'
* updating rule logic
* updating mitre mapping
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit c58d59eeb7 )
2025-04-21 16:11:13 +00:00
Terrance DeJesus
de507603ac
[New Rule] Adding Coverage for AWS IAM Virtual MFA Device Registration ( #4626 )
...
* adding new rule 'AWS IAM Virtual MFA Device Registration Attempt with Session Token'
* updating rule
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit 94237798a5 )
2025-04-21 15:06:35 +00:00
Terrance DeJesus
e276d8ef91
[New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses ( #4624 )
...
* adding new rule 'AWS STS Temporary IAM Session Token Used from Multiple Addresses'
* updating rule assets
* updating mitre mapping
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit 96c2d0ca85 )
2025-04-17 20:10:48 +00:00
Terrance DeJesus
80a3f7f405
[Rule Tuning] Tuning Azure Service Principal Credentials Added ( #4570 )
...
* tuning 'Azure Service Principal Credentials Added'
* updated patch version
* added investigation guide
* updating patch version
* updating patch version
(cherry picked from commit ba16e27edb )
2025-04-16 18:02:48 +00:00
Terrance DeJesus
2bb46f4c7b
[Rule Tuning] Adjusting Microsoft Entra ID Rare Authentication Requirement for Principal User ( #4562 )
...
* tuning 'Microsoft Entra ID Rare Authentication Requirement for Principal User'
* updated MITRE ATT&CK mappings
* updated index target
* updated patch version
* updating patch version
* bumping patch version
* updating patch version
(cherry picked from commit 1a6669e5a6 )
2025-04-16 16:26:15 +00:00
Jonhnathan
9f7dd9891b
[Rule Tuning] Suspicious WMI Event Subscription Created ( #4618 )
...
* [Rule Tuning] Suspicious Execution via Scheduled Task
* [Rule Tuning] Suspicious WMI Event Subscription Created
(cherry picked from commit e11fe78846 )
2025-04-16 13:10:23 +00:00
Jonhnathan
e0f689f18e
[Rule Tuning] SSH Authorized Keys File Deletion ( #4591 )
...
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 3eed0f5b6a )
2025-04-15 15:20:58 +00:00
Ruben Groenewoud
50758935f6
[D4C Conversion] Converting Compatible D4C Rules to DR ( #4532 )
...
* [D4C Conversion] Converting Compatible D4C Rules to DR
* added host.os.type
* Rename
* Update rules/linux/execution_container_management_binary_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_debugfs_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/linux/privilege_escalation_mount_launched_inside_container.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 3b1f780435 )
2025-04-10 12:31:24 +00:00
Ruben Groenewoud
2a07268bdb
[FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… ( #4529 )
...
* [FN Tuning] Shared Object Created or Changed by Previously Unknown Process
* Update process exclusions in TOML file
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: shashank-elastic <91139415+shashank-elastic@users.noreply.github.com >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com >
(cherry picked from commit 05c9f6bbdb )
2025-04-08 16:23:58 +00:00
Jonhnathan
0725866926
[Rule Tuning] Suspicious Execution via Scheduled Task ( #4599 )
...
(cherry picked from commit a5d9d6400a )
2025-04-07 17:33:36 +00:00
shashank-elastic
a0538f2ce9
Add investigation guides ( #4600 )
...
(cherry picked from commit 3966981dae )
2025-04-07 15:55:32 +00:00
Mika Ayenson
22eb203042
Backport macOS rules indicidently missed with backport:skip label
2025-04-07 10:51:46 -05:00
Jonhnathan
182d9e6c47
[Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules ( #4592 )
...
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 9577d53284 )
2025-04-07 15:04:31 +00:00
Jonhnathan
bbbf20577f
[Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation ( #4589 )
...
(cherry picked from commit e7806fc74f )
2025-04-02 12:56:54 +00:00
Samirbous
65bc676bc3
Update defense_evasion_microsoft_defender_tampering.toml ( #4573 )
...
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
(cherry picked from commit 6d8cfda10f )
2025-04-01 17:08:57 +00:00
Terrance DeJesus
23f4214ede
[Rule Tuning] Tuning Illicit Grant Consent Detections in Azure and M365 ( #4557 )
...
* tuning Azure rule for illicit grant activity; creating new rule for M365
* Update rules/integrations/o365/initial_access_microsoft_365_illicit_consent_grant_via_registered_application.toml
* Update rules/integrations/azure/initial_access_entra_illicit_consent_grant_via_registered_application.toml
* adjusted tags
* Update rules/integrations/azure/initial_access_entra_illicit_consent_grant_via_registered_application.toml
(cherry picked from commit c6e37d6910 )
2025-03-27 19:59:17 +00:00
Terrance DeJesus
f87bf0e631
tuning 'Azure Conditional Access Policy Modified' ( #4558 )
...
(cherry picked from commit 280140650a )
2025-03-27 19:48:01 +00:00
Terrance DeJesus
737e4c8997
deprecating 'Azure Virtual Network Device Modified or Deleted' ( #4559 )
...
(cherry picked from commit 2f3f4fbdef )
2025-03-27 14:14:14 +00:00
shashank-elastic
fb95abc9ed
Update Max signals value to supported limits ( #4556 )
...
(cherry picked from commit 2b3095a13c )
2025-03-27 03:36:48 +00:00
M. Visser
4b84ce5ec5
[Rule Tuning] Added OWA (outlook for web) new AppID ( #4568 )
...
* Added OWA (outlook for web) new AppID
**Title:** Add new Outlook for Web AppID to abnormal Microsoft 365 ClientAppID rule
**Description:**
This pull request updates the `initial_access_microsoft_365_abnormal_clientappid` rule to include the newly introduced Outlook for Web AppID:
- **New AppID**: `9199bf20-a13f-4107-85dc-02114787ef48`
### Context
Outlook for Web (OWA) is migrating to a new authentication platform using MSAL and a Single Page Application (SPA) auth model. As part of this backend change, Microsoft is replacing the existing OWA AppID with a new one. This change is being rolled out during the first half of calendar year 2024, with full deployment expected by Q4 2024.
- **Old OWA AppID**: `00000002-0000-0ff1-ce00-000000000000`
- **New OWA AppID**: `9199bf20-a13f-4107-85dc-02114787ef48`
Although no action is required for tenant administrators, this new AppID may show up in logs and should be accounted for in detections relying on known legitimate ClientAppIDs.
### Why this change?
The rule `initial_access_microsoft_365_abnormal_clientappid` flags potentially suspicious or unauthorized client applications accessing Microsoft 365 services. To prevent false positives caused by this official change from Microsoft, this PR adds the new OWA AppID to the allowlist.
### References
- Microsoft 365 Message Center notice (ref: MC715025)
- [MSAL documentation](https://learn.microsoft.com/en-us/azure/active-directory/develop/msal-overview )
* Update initial_access_microsoft_365_abnormal_clientappid.toml
Updated updated_date
(cherry picked from commit 63c1f47689 )
2025-03-26 18:19:49 +00:00
shashank-elastic
31d65ad1e1
Prep main for 9.1 ( #4555 )
...
* Prep for Release 9.1
* Update Patch Version
* Update Patch version
* Update Patch version
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit e8c54169a4 )
2025-03-26 15:08:47 +00:00
Terrance DeJesus
ca92be94ab
fixing double header in investigation notes ( #4490 )
...
(cherry picked from commit 5e12f05a36 )
2025-03-25 13:13:25 +00:00
Terrance DeJesus
eca4463108
[New Rule] Adding Coverage for DynamoDB Exfiltration Behaviors ( #4535 )
...
* new rules for AWS DynamoDB data exfiltration
* bumping patch version
* adjusting investigation guide
* updating patch version
* updating patch version
* updating patch version
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
(cherry picked from commit db78756062 )
2025-03-21 14:10:27 +00:00
shashank-elastic
a1dd22efbe
Prep for Release 9.0 ( #4550 )
...
Removed changes from:
- detection_rules/etc/packages.yaml
(selectively cherry picked from commit 059d7efa25 )
2025-03-20 15:07:35 +00:00
Kirti Sodhi
955e973c00
Change description and name of problemchild ML detection-rules ( #4545 )
...
Changed description and name of problemchild ML detection-rules
2025-03-20 08:58:10 -04:00
Samirbous
28a06fd25f
Update defense_evasion_posh_assembly_load.toml ( #4543 )
...
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2025-03-20 05:13:28 -03:00
Eric Forte
5ccb7ed4af
Min stack rules from 4516 ( #4549 )
2025-03-19 20:27:30 -04:00
Eric Forte
5b3dc4a4a7
Revert "Add new ML detection rules for Privileged Access Detection ( #4516 )" ( #4548 )
...
This reverts commit 2ff8d1bb56 .
2025-03-19 20:08:08 -04:00
Kirti Sodhi
2ff8d1bb56
Add new ML detection rules for Privileged Access Detection ( #4516 )
...
Add detection-rules for privileged access detection integration
2025-03-19 11:02:28 -04:00
shashank-elastic
0993ced309
Deprecate Cloud Defend Rules ( #4537 )
2025-03-14 21:27:37 +05:30