Commit Graph

509 Commits

Author SHA1 Message Date
Ruben Groenewoud 628207bbca [New Rule] Attempt to Clear Logs via Journalctl (#5170)
(cherry picked from commit 949cb751ca)
2025-10-06 11:54:53 +00:00
Terrance DeJesus 391e24cc41 tuning 'Unusual Instance Metadata Service (IMDS) API Request' (#5163)
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

(cherry picked from commit 1833d2e7a0)
2025-10-06 11:21:52 +00:00
Ruben Groenewoud 39aa369e94 [New Rule] Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt (#5166)
* [New Rule] Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt

* Added additional 3rd party EDR compatibility

* Update privilege_escalation_cve_2025_41244_vmtoolsd_lpe.toml

* Add crowdstrike compatibility

* ++

* Update privilege_escalation_cve_2025_41244_vmtoolsd_lpe.toml

(cherry picked from commit 25880e73da)
2025-10-06 11:04:18 +00:00
Ruben Groenewoud 4ffed362ff [Rule Tuning] Misc. Linux Community Tunings (#5160)
* [Rule Tuning] Misc. Linux Community Tunings

* ++

* Fix query syntax in execution_unusual_path_invocation rule

* Refactor process.parent conditions for clarity

(cherry picked from commit be3af09d9d)
2025-10-06 10:08:17 +00:00
Ruben Groenewoud 296b7754fc [New Rules] Potential CVE-2025-32463 Exploitation (#5169)
* [New Rules] Potential CVE-2025-32463 Exploitation

* Update chroot rule logic

* Added IGs

* Update rules/linux/privilege_escalation_cve_2025_32463_nsswitch_file_creation.toml

* Update rules/linux/privilege_escalation_cve_2025_32463_nsswitch_file_creation.toml

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

---------

Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>

(cherry picked from commit 5d69eb19ba)
2025-10-01 09:41:44 +00:00
Ruben Groenewoud 706c0daff9 [Rule Tuning] Potential Port Scanning Activity from Compromised Host (#5161)
* [Rule Tuning] Potential Port Scanning Activity from Compromised Host

* Update rules/linux/discovery_port_scanning_activity_from_compromised_host.toml

* Update port scanning detection query

Refine query to include source IP and limit destination port range.

* Update discovery_port_scanning_activity_from_compromised_host.toml

* Update query in discovery port scanning rule

* Update discovery_port_scanning_activity_from_compromised_host.toml

(cherry picked from commit 8319b7f5d8)
2025-09-30 14:38:06 +00:00
Ruben Groenewoud 19f02434bc [New Rule] Node.js Pre or Post-Install Script Execution (#5131)
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>

(cherry picked from commit 53a2233e9b)
2025-09-29 19:51:31 +00:00
Ruben Groenewoud 1f7a782b4f [New Rule] GitHub Authentication Token Access via Node.js (#5130)
(cherry picked from commit 9f5793759c)
2025-09-24 18:50:43 +00:00
Ruben Groenewoud 6ea9f7a698 [New Rule] Curl or Wget Spawned via Node.js (#5132)
* [New Rule] Curl or Wget Spawned via Node.js

* Update command_and_control_curl_wget_spawn_via_nodejs_parent.toml

(cherry picked from commit 53b4e92861)
2025-09-22 09:00:43 +00:00
Mika Ayenson, PhD eb0653f37e [Rule Tuning] Beats & Endgame Indices (#5072)
(cherry picked from commit 392e0253c3)
2025-09-09 18:21:38 +00:00
Ruben Groenewoud 1a5dacfca4 [Rule Tuning] D-Bus Service Created (#5076)
(cherry picked from commit 0f0f16bdee)
2025-09-09 13:36:15 +00:00
Ruben Groenewoud 54b19e7801 [Rule Tuning] Misc. Linux ES|QL Rules (#5050)
* [Rule Tuning] Misc. Linux ES|QL Rules

* update date bump

* ++

* Update persistence_web_server_sus_child_spawned.toml

* Update working directory conditions in TOML file

(cherry picked from commit ef7ff52119)
2025-09-02 11:51:36 +00:00
shashank-elastic fe12efe85e Monthly Schema Updates (#5046)
(cherry picked from commit 93ac471574)
2025-09-01 15:15:04 +00:00
Ruben Groenewoud d489f28daa [New Rule] Multi-Base64 Decoding Attempt from Suspicious Location (#4931)
* [New Rule] Multi-Base64 Decoding Attempt from Suspicious Location

* ++

* Update rules/linux/defense_evasion_multi_base64_decoding_attempt.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update rules/linux/defense_evasion_multi_base64_decoding_attempt.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit a4a5b171c4)
2025-08-25 08:33:36 +00:00
Terrance DeJesus 27fcbde250 [Rule Tuning] ESQL Query Field Dynamic Field Standardization (#4912)
* adjusted Potential Widespread Malware Infection Across Multiple Hosts

* adjusted Microsoft Azure or Mail Sign-in from a Suspicious Source

* adjusted AWS EC2 Multi-Region DescribeInstances API Calls

* adjusted AWS Discovery API Calls via CLI from a Single Resource

* adjusted AWS Service Quotas Multi-Region  Requests

* adjusted AWS EC2 EBS Snapshot Shared or Made Public

* adjusted AWS S3 Bucket Enumeration or Brute Force

* adjusted AWS EC2 EBS Snapshot Access Removed

* adjusted Potential AWS S3 Bucket Ransomware Note Uploaded

* adjusted AWS S3 Object Encryption Using External KMS Key

* adjusted AWS S3 Static Site JavaScript File Uploaded

* adjusted AWS Access Token Used from Multiple Addresses

* adjusted AWS Signin Single Factor Console Login with Federated User

* adjusted AWS IAM AdministratorAccess Policy Attached to Group

* adjusted AWS IAM AdministratorAccess Policy Attached to Role

* adjusted AWS IAM AdministratorAccess Policy Attached to User

* adjusted AWS Bedrock Invocations without Guardrails Detected by a Single User Over a Session

* adjusted AWS Bedrock Guardrails Detected Multiple Violations by a Single User Over a Session

* adjusted AWS Bedrock Guardrails Detected Multiple Policy Violations Within a Single Blocked Request

* adjusted Unusual High Confidence Content Filter Blocks Detected

* adjusted Potential Abuse of Resources by High Token Count and Large Response Sizes

* AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User

* Unusual High Denied Sensitive Information Policy Blocks Detected

* adjusted Unusual High Denied Topic Blocks Detected

* adjusted AWS Bedrock Detected Multiple Validation Exception Errors by a Single User

* adjusted Unusual High Word Policy Blocks Detected

* adjusted Microsoft Entra ID Concurrent Sign-Ins with Suspicious Properties

* adjusted Azure Entra MFA TOTP Brute Force Attempts

* adjusted Microsoft Entra ID Sign-In Brute Force Activity

* adjusted Microsoft Entra ID Exccessive Account Lockouts Detected

* adjusted Microsoft 365 Brute Force via Entra ID Sign-Ins

* deprecated Azure Entra Sign-in Brute Force Microsoft 365 Accounts by Repeat Source

* adjusted Microsoft Entra ID Session Reuse with Suspicious Graph Access

* adjusted Suspicious Microsoft OAuth Flow via Auth Broker to DRS

* adjusted Potential Denial of Azure OpenAI ML Service

* adjusted Azure OpenAI Insecure Output Handling

* adjusted Potential Azure OpenAI Model Theft

* adjusted M365 OneDrive Excessive File Downloads with OAuth Token

* adjusted Multiple Microsoft 365 User Account Lockouts in Short Time Window

* adjusted Potential Microsoft 365 User Account Brute Force

* adjusted Suspicious Microsoft 365 UserLoggedIn via OAuth Code

* adjusted Multiple Device Token Hashes for Single Okta Session

* adjusted Multiple Okta User Authentication Events with Client Address

* adjusted Multiple Okta User Authentication Events with Same Device Token Hash

* adjusted High Number of Okta Device Token Cookies Generated for Authentication

* adjusted Okta User Sessions Started from Different Geolocations

* adjusted High Number of Egress Network Connections from Unusual Executable

* adjusted Unusual Base64 Encoding/Decoding Activity

* adjusted Potential Port Scanning Activity from Compromised Host

* adjusted Potential Subnet Scanning Activity from Compromised Host

* adjusted Unusual File Transfer Utility Launched

* adjusted Potential Malware-Driven SSH Brute Force Attempt

* adjusted Unusual Process Spawned from Web Server Parent

* adjusted Unusual Command Execution from Web Server Parent

* adjusted  Rare Connection to WebDAV Target

* adjusted Potential PowerShell Obfuscation via Invalid Escape Sequences

* adjusted Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion

* adjusted Unusual File Creation by Web Server

* adjusted Potential PowerShell Obfuscation via High Special Character Proportion

* adjusted Potential Malicious PowerShell Based on Alert Correlation

* adjusted Potential PowerShell Obfuscation via Character Array Reconstruction

* adjusted Potential PowerShell Obfuscation via String Reordering

* adjusted Potential PowerShell Obfuscation via String Concatenation

* adjusted Potential PowerShell Obfuscation via Reverse Keywords

* adjusted PowerShell Obfuscation via Negative Index String Reversal

* adjusted Dynamic IEX Reconstruction via Method String Access

* adjusted Potential Dynamic IEX Reconstruction via Environment Variables

* adjusted Potential PowerShell Obfuscation via High Numeric Character Proportion

* adjusted Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation

* adjusted Rare Connection to WebDAV Target

* adjusted Potential PowerShell Obfuscation via Invalid Escape Sequences

* adjusted Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion

* adjusted Potential PowerShell Obfuscation via Character Array Reconstruction

* adjusted Potential PowerShell Obfuscation via High Special Character Proportion

* adjusted Potential PowerShell Obfuscation via Special Character Overuse

* adjusted Potential PowerShell Obfuscation via String Reordering

* adjusted Suspicious Microsoft 365 UserLoggedIn via OAuth Code

* adjusted fields that were inconsistent

* adjusted additional fields

* adjusted esql to Esql

* adjusted several rules for common field names

* updating rules

* updated dates

* updated dates

* updated ESQL fields

* lowercase all functions and logical operators

* adjusted dates for unit tests

* Update Esql_priv to Esql_temp as these don't hold PII

* PowerShell adjustments

* Make query comments consistent

* update comment

* reverted 2856446a-34e6-435b-9fb5-f8f040bfa7ed

* Update rules/windows/discovery_command_system_account.toml

* removed dot notation

---------

Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>

(cherry picked from commit b28338c680)
2025-08-05 23:37:57 +00:00
shashank-elastic bef2a1f11a Investigation guides Update (#4920)
(cherry picked from commit 2a73a572fb)
2025-07-22 02:24:58 +00:00
Ruben Groenewoud 8bb65a304b [New Rule] Potential Impersonation Attempt via Kubectl (#4833)
* [New Rule] Potential Impersonation Attempt via Kubectl

* ++

* Update defense_evasion_potential_kubectl_impersonation.toml

(cherry picked from commit 5c901841a3)
2025-07-21 08:05:20 +00:00
Ruben Groenewoud 0f945fda13 [New Rule] Unusual Kill Signal (#4911)
* [New Rule] Unusual Kill Signal

* Update defense_evasion_unsual_kill_signal.toml

* Update defense_evasion_unsual_kill_signal.toml

(cherry picked from commit d510a965e9)
2025-07-17 13:07:52 +00:00
shashank-elastic 03c20ec798 Fix pipe characters in rule descriptions (#4893)
(cherry picked from commit b70792082a)
2025-07-10 09:43:20 +00:00
shashank-elastic 008dce0c6f Add investigation guides for detection rules (#4886)
(cherry picked from commit 7175b3ab06)
2025-07-07 18:57:53 +00:00
shashank-elastic f036cb90fe Prep 8.19/9.1 (#4869)
* Prep 8.19/9.1 Release

* Download Beats Schema

* Download API Schema

* Download 8.18.3 Beats Schema

* Download Latest Integrations manifest and schema

* Comment old schemas

* Update Patch version

Removed changes from:
- detection_rules/etc/packages.yaml

(selectively cherry picked from commit 9b292b97ea)
2025-07-07 15:30:11 +00:00
Ruben Groenewoud 889ae36b19 [New Rule] Kubectl Apply Pod from URL (#4855)
* [New Rule] Kubectl Apply Pod from URL

* Update execution_kubectl_apply_pod_from_url.toml

(cherry picked from commit 715e3f44f4)
2025-07-03 08:51:44 +00:00
Ruben Groenewoud 6241e3a058 [Rule Tuning] Potential Linux Tunneling and/or Port Forwarding (#4858)
(cherry picked from commit 26e35fd03b)
2025-07-03 07:54:51 +00:00
Ruben Groenewoud 2e4c29d32d [New Rule] Kubernetes Sensitive Configuration File Activity (#4849)
* [New Rule] Kubernetes Sensitive Configuration File Activity

* Update rules/linux/persistence_kubernetes_sensitive_file_activity.toml

(cherry picked from commit 3efcd70f8c)
2025-07-02 15:20:44 +00:00
Ruben Groenewoud a9fe0aa68d [New Rule] Potential Kubectl Masquerading (#4832)
* [New Rule] Potential Kubectl Masquerading

* Update defense_evasion_potential_kubectl_masquerading.toml

* ++

* ++

* Update defense_evasion_potential_kubectl_masquerading.toml

* Update rules/linux/defense_evasion_potential_kubectl_masquerading.toml

(cherry picked from commit 0847c32333)
2025-06-30 11:52:03 +00:00
Ruben Groenewoud 2e5fb2dc50 [New Rule] Kubectl Network Configuration Modification (#4836)
* [New Rule] Kubectl Network Configuration Modification

* ++

(cherry picked from commit bc87ca1d5b)
2025-06-30 08:57:39 +00:00
Ruben Groenewoud 346794bf33 [New Rule] Kubernetes Direct API Request via Curl or Wget (#4841)
(cherry picked from commit 786542a9d4)
2025-06-30 08:38:10 +00:00
Ruben Groenewoud 193ffe1d71 [Deprecation] Suspicious File Creation in /etc for Persistence (#4850)
* [Deprecation] Suspicious File Creation in /etc for Persistence

* [Deprecation] Suspicious File Creation in /etc for Persistence

* Update persistence_etc_file_creation.toml

* Fix

(cherry picked from commit 7c07033354)
2025-06-27 08:19:26 +00:00
Ruben Groenewoud ada1f7719f [Rule Tuning] Added Kubernetes Data Source Tag (#4831)
(cherry picked from commit e666cabb3d)
2025-06-24 11:23:14 +00:00
Ruben Groenewoud d52c408483 [New Rule] Kubernetes Service Account Secret Access (#4816)
(cherry picked from commit dd4576d127)
2025-06-18 04:05:56 +00:00
Ruben Groenewoud 1ac0d74d78 [New Rule] Kubeconfig File Creation or Modification (#4810)
* [New Rule] Kubeconfig File Creation or Modification

* Update lateral_movement_kubeconfig_file_activity.toml

(cherry picked from commit 386a4b85eb)
2025-06-17 13:05:30 +00:00
Ruben Groenewoud 15d2258858 [New Rule] Kubeconfig File Discovery (#4811)
* [New Rule] Kubeconfig File Discovery

* Update discovery_kubeconfig_file_discovery.toml

(cherry picked from commit 6bc808916b)
2025-06-17 12:46:58 +00:00
Ruben Groenewoud 0eb37f5b68 [Rule Tuning] Container Management Utility Run Inside A Container (#4809)
* [Rule Tuning] Container Management Utility Run Inside A Container

* ++

(cherry picked from commit 103fbf12c8)
2025-06-17 12:35:10 +00:00
Ruben Groenewoud ec9b09c0a4 [New Rule] Kubectl Permission Discovery (#4812)
(cherry picked from commit dfd46a09e8)
2025-06-17 12:19:08 +00:00
Ruben Groenewoud fbdb2e10ff [Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765)
(cherry picked from commit b2887e592b)
2025-06-05 11:17:01 +00:00
Ruben Groenewoud ad6972ccb8 [Rule Tuning] Shell Configuration Creation or Modification (#4766)
(cherry picked from commit ba9f76c6b5)
2025-06-04 09:31:20 +00:00
Ruben Groenewoud 0605d754a3 [New Rule] Unusual Exim4 Child Process (#4684)
(cherry picked from commit 3a601a10fb)
2025-05-06 17:01:48 +00:00
Ruben Groenewoud 65791ff7c8 [New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683)
(cherry picked from commit c145e33f16)
2025-05-06 16:43:13 +00:00
Ruben Groenewoud 8fe54e1785 [New Rule] Linux Telegram API Request (#4677)
(cherry picked from commit 608e02e27e)
2025-05-06 16:27:45 +00:00
Ruben Groenewoud d196211d68 [New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685)
(cherry picked from commit 944428d81e)
2025-05-06 15:56:24 +00:00
Ruben Groenewoud 427c617f3b [New Rule] System Binary Symlink to Suspicious Location (#4682)
(cherry picked from commit fdc6b09d54)
2025-05-06 12:21:27 +00:00
Ruben Groenewoud 66c8faaa65 [New Rule] Suspicious Named Pipe Creation (#4681)
(cherry picked from commit 25dc8498ae)
2025-05-06 12:05:07 +00:00
Ruben Groenewoud e1506c7f6e [New Rule] Suspicious Kernel Feature Activity (#4676)
(cherry picked from commit 8b08795e00)
2025-05-06 11:48:07 +00:00
Ruben Groenewoud 453826355a [New Rule] Potential Data Exfiltration Through Curl (#4678)
(cherry picked from commit 0193af2842)
2025-05-06 11:32:34 +00:00
Ruben Groenewoud 0855f2b198 [New/Tuning] Potential Hex Payload Execution via Command-Line (#4675)
(cherry picked from commit 4030de9295)
2025-05-06 11:03:19 +00:00
Ruben Groenewoud 261b6a2a59 [New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674)
(cherry picked from commit eb3520a63b)
2025-05-06 10:47:36 +00:00
Ruben Groenewoud 86cd02217d [New Rule] Git Repository or File Download to Suspicious Directory (#4663)
(cherry picked from commit 403e20c2c6)
2025-05-06 09:40:01 +00:00
Ruben Groenewoud 38734aba83 [New Rule] Manual Mount Discovery via /etc/exports (#4662)
(cherry picked from commit 3f9e2edcb5)
2025-05-06 09:23:28 +00:00
Ruben Groenewoud 552f0acfaf [New Rule] Docker Release File Creation (#4661)
(cherry picked from commit a9e8a78c09)
2025-05-06 09:06:09 +00:00
Ruben Groenewoud 8756bb5513 [New Rule] Manual Memory Dumping via Proc Filesystem (#4660)
(cherry picked from commit 13cf424ef5)
2025-05-06 08:50:39 +00:00