Commit Graph

344 Commits

Author SHA1 Message Date
github-actions[bot] 5911801621 Lock versions for releases: 8.19,9.2,9.3,9.4 (#6044)
(cherry picked from commit 0b15511ef5)
2026-05-04 16:03:02 +00:00
shashank-elastic e1a4dcd05a Monthly Manifest and Schema Updation (#6036)
(cherry picked from commit a6fba3c728)
2026-05-04 12:35:37 +00:00
github-actions[bot] 280609129e Lock versions for releases: 8.19,9.2,9.3,9.4 (#5998)
(cherry picked from commit cb3c342b31)
2026-04-28 19:25:32 +00:00
Mika Ayenson, PhD aeb81cd80e [FR] Add enforcement for deprecated_reason (#5953)
(cherry picked from commit b6886f310c)
2026-04-23 11:48:56 +00:00
github-actions[bot] 16901d9920 Lock versions for releases: 8.19,9.2,9.3,9.4 (#5972)
* Locked versions for releases: 8.19,9.2,9.3,9.4

---------

Co-authored-by: shashank-elastic <shashank-elastic@users.noreply.github.com>

(cherry picked from commit 2dac152094)
2026-04-23 00:18:28 +00:00
shashank-elastic b3c38c17c5 Prep for Release 9.4 (#5965)
Removed changes from:
- detection_rules/etc/packages.yaml

(selectively cherry picked from commit 7a54f8be99)
2026-04-22 18:46:33 +00:00
Susan e7efeeb64f Add Entity related integrations ML rules with _ea job IDs and min_stack_version 9.4.0 (#5909)
Co-authored-by: Shashank K S <Shashank.Suryanarayana@elastic.co>

Removed changes from:
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_geo_country_iso_code.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_ip.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_port.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_destination_region_name.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_written_to_external_device.toml
- rules/integrations/ded/exfiltration_ml_high_bytes_written_to_external_device_airdrop.toml
- rules/integrations/ded/exfiltration_ml_rare_process_writing_to_external_device.toml
- rules/integrations/dga/command_and_control_ml_dga_high_sum_probability.toml
- rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_process_args.toml
- rules/integrations/lmd/lateral_movement_ml_high_mean_rdp_session_duration.toml
- rules/integrations/lmd/lateral_movement_ml_high_remote_file_size.toml
- rules/integrations/lmd/lateral_movement_ml_high_variance_rdp_session_duration.toml
- rules/integrations/lmd/lateral_movement_ml_rare_remote_file_directory.toml
- rules/integrations/lmd/lateral_movement_ml_rare_remote_file_extension.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_connections_from_a_source_ip.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_connections_to_a_destination_ip.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_rdp_processes.toml
- rules/integrations/lmd/lateral_movement_ml_spike_in_remote_file_transfers.toml
- rules/integrations/lmd/lateral_movement_ml_unusual_time_for_an_rdp_session.toml
- rules/integrations/pad/privileged_access_ml_linux_high_count_privileged_process_events_by_user.toml
- rules/integrations/pad/privileged_access_ml_linux_high_median_process_command_line_entropy_by_user.toml
- rules/integrations/pad/privileged_access_ml_linux_rare_process_executed_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_high_sum_concurrent_sessions_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_host_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_region_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_rare_source_ip_by_user.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_application_assignment_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_lifecycle_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_membership_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_group_privilege_changes.toml
- rules/integrations/pad/privileged_access_ml_okta_spike_in_user_lifecycle_management_changes.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_group_management_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_special_logon_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_special_privilege_use_events.toml
- rules/integrations/pad/privileged_access_ml_windows_high_count_user_account_management_events.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_device_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_group_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_privilege_assigned_to_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_region_name_by_user.toml
- rules/integrations/pad/privileged_access_ml_windows_rare_source_ip_by_user.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_host.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_parent_process.toml
- rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_user.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_host.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_parent_process.toml
- rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_user.toml

(selectively cherry picked from commit d8a39869c5)
2026-04-22 12:10:39 +00:00
github-actions[bot] 8fdebb28e1 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5930)
(cherry picked from commit c601edfbb3)
2026-04-08 14:18:11 +00:00
github-actions[bot] af299e0eba Lock versions for releases: 8.19,9.1,9.2,9.3 (#5926)
(cherry picked from commit 88bc42265f)
2026-04-07 12:18:54 +00:00
Terrance DeJesus 3555a1e455 [Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field (#5894)
* [Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field
Fixes #5893

* adding non-admin consented filter

* converting to ESQL

* additional query adjustments

* adjusted query KEEP

* updating non-ecs

* Apply suggestion from @terrancedejesus

(cherry picked from commit 48128c1c66)
2026-04-06 13:44:00 +00:00
shashank-elastic b212b283f7 Monthly Manifest and Schema Updation (#5920)
(cherry picked from commit 199a4d6160)
2026-04-06 12:09:16 +00:00
github-actions[bot] 518496c9d7 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5888)
* Locked versions for releases: 8.19,9.1,9.2,9.3

* Update pyproject.toml

---------

Co-authored-by: Mikaayenson <Mikaayenson@users.noreply.github.com>

(cherry picked from commit d9890db6ff)
2026-03-26 17:35:40 +00:00
Terrance DeJesus 6e1acda7f2 [New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme (#5878)
* [New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme
Fixes #5877

* adding microsoft_exchange_online_message_trace to manifests/schemas; bumping patch

* updated mitre

* Update rules/integrations/microsoft_exchange_online_message_trace/initial_access_azure_monitor_callback_phishing_email.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* bumping patch

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit cd19b25485)
2026-03-26 15:54:19 +00:00
Eric Forte 6fc8f5fdc8 [FR] [DaC] Add fine-grained bypass env var for ES|QL keep and metadata validation (#5869)
* Add fine grain 'keep' req bypass

* Add metadata bypass

(cherry picked from commit 75ffa5ec4e)
2026-03-24 18:40:45 +00:00
github-actions[bot] 05c5c5cdc5 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5875)
(cherry picked from commit b14dec9efa)
2026-03-23 18:19:23 +00:00
Mika Ayenson, PhD a92f48c522 [New Rules] External Promotion Alert for IBM QRadar (#5843)
(cherry picked from commit ade7de7be4)
2026-03-20 19:46:29 +00:00
Ruben Groenewoud 9737dfeafe [Rule Tuning] Added Traefik Compatibility to Web Server Access Rules (#5837)
* [Rule Tuning] Added Traefik Compatibility to Web Server Access Rules

* ++

* Bump pyproject.toml

* Bump pyproject.toml

(cherry picked from commit 8b140d5811)
2026-03-17 16:35:46 +00:00
Terrance DeJesus eeffdd5a7c [New Rule] Azure Arc Kubernetes Cluster Connect Abuse (#5824)
* [New Rule] Azure Arc Kubernetes Cluster Connect Abuse
Fixes #5823

* rename, adjusted query

* adding KEEP *

* adjusting maturity

* added to non-ecs schema

* updating rule

* addressing unit test failures

* adjustments to logic, mitre mappings, unit test failures, etc.

* Update rules/integrations/azure/initial_access_azure_arc_cluster_credential_access_unusual_source.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 937a7a35e6)
2026-03-17 15:11:23 +00:00
Mika Ayenson, PhD edec022dcd [FR] Reset deprecated lock to the latest state during lock (#5827)
(cherry picked from commit 49c9c283e6)
2026-03-16 22:09:47 +00:00
github-actions[bot] 6305a3890f Lock versions for releases: 8.19,9.1,9.2,9.3 (#5820)
(cherry picked from commit 61211a2670)
2026-03-10 13:23:51 +00:00
github-actions[bot] e6102a3cf8 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5818)
(cherry picked from commit 87badac5a0)
2026-03-10 10:07:06 +00:00
shashank-elastic 1ae6168b80 Monthly Manifest and Schema Updation (#5816)
* Monthly Manifest and Schema Updation

* Update Patch Version

(cherry picked from commit e08f234b1c)
2026-03-09 13:18:58 +00:00
Terrance DeJesus 2108fa8423 [New Rule] Microsoft 365 SharePoint/OneDrive Sensitive Search and File Access (#5777)
* [New Rule] Microsoft 365 SharePoint/OneDrive Sensitive Search and File Access
Fixes #5776

* adjusting UUIDs

* added additional strings

* adjusted investigation guide

* fixed mitre mappings

* fixed mitre mappings

* Apply suggestion from @terrancedejesus

(cherry picked from commit 5ecbc0f0b9)
2026-02-26 19:33:06 +00:00
Terrance DeJesus b950cbc6a7 [New Rule] M365 MFA Notification Email Deleted or Moved (#5779)
* [New Rule] M365 MFA Notification Email Deleted or Moved
Fixes #5778

* updated non-ecs

* adjusted rule name

* Apply suggestion from @terrancedejesus

(cherry picked from commit 71c461d867)
2026-02-26 18:25:06 +00:00
Terrance DeJesus 4437172439 [New Rule] Okta User Authentication via Proxy Followed by Security Alert (#5752)
* [New Rule] Okta User Authentication via Proxy Followed by Security Alert
Fixes #5751

* adjusted to EQL

* fixed syntax

* Update rules/integrations/okta/initial_access_first_occurrence_user_session_started_via_proxy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* removed defense evasion; adjusted maxspan to 30m

* removed Okta tag

* adding Okta back as integration tag

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit 8593116f58)
2026-02-26 16:36:06 +00:00
Terrance DeJesus 19b80d503d [Rule Tuning] M365 OneDrive/SharePoint Excessive File Downloads (#5767)
* [Rule Tuning] M365 OneDrive/SharePoint Excessive File Downloads
Fixes #5766

* updated non-ecs

* fixing keep command

(cherry picked from commit 04ad018f27)
2026-02-26 15:43:04 +00:00
github-actions[bot] 2c27b7075c Lock versions for releases: 8.19,9.1,9.2,9.3 (#5765)
(cherry picked from commit 92a379e034)
2026-02-24 13:23:35 +00:00
Terrance DeJesus 7c711c3ae9 [Rule Tuning] Entra ID Federated Identity Credential Persistence Detection (#5702)
* [Rule Tuning] Entra ID Federated Identity Credential Persistence Detection
Fixes #5701

* updated mitre mapping ID

* adjusted mitre mappings; non-ecs schema file

* fixed trailing comma in non-ecs; adjusted file name

* adjusted file name; fixed non-ecs schema for upstream ESQL validation

* Apply suggestion from @terrancedejesus

* Apply suggestion from @terrancedejesus

* changed lookback to 9 minutes; adjusted keep values

* added setup; added tag

(cherry picked from commit f773103519)
2026-02-19 21:02:43 +00:00
Terrance DeJesus 4385869486 [Rule Tuning] Entra ID SharePoint Accessed by Unusual User and Microsoft Authentication Broker Client (#5681)
* [Rule Tuning] Transform Dormant SharePoint Rule to Detect OAuth Phishing
Fixes #5680

* adjusted query format for unit test; added additional domain tag for storage

* Apply suggestion from @terrancedejesus

* Fix formatting in non-ecs-schema.json

* adjusted description

* re-order mappings

(cherry picked from commit 63f76cf004)
2026-02-19 15:13:37 +00:00
Terrance DeJesus 676d1664da [Rule Tuning] Okta User Assigned Administrator Role (#5671)
Fixes #5670

(cherry picked from commit 62cc9f105d)
2026-02-12 14:37:32 +00:00
github-actions[bot] 8acd433614 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5708)
(cherry picked from commit df9c27d82e)
2026-02-10 05:48:20 +00:00
shashank-elastic 80f99ded67 Monthly Manifest and Schema Updation (#5697)
(cherry picked from commit 70d7f2b6b1)
2026-02-10 03:51:19 +00:00
Ruben Groenewoud c9b3f62d42 [New Rules] Misc. K8s RBAC Abuse Rules (#5673)
* Updated kubernetes.audit.requestObject.spec.containers.image type of text to Keyword

* [New Rules] Misc. K8s RBAC Abuse Rules

* --

* Update non-ecs-schema

* Update to make unit tests happy

* Mitre mapping updates

* Fix query logic for service account role bindings

* Fix formatting in persistence_service_account_bound_to_clusterrole rule

(cherry picked from commit 64a08cd6af)
2026-02-05 16:45:57 +00:00
Samirbous e7fccaefdb [New] Multiple Machine Learning Alerts by Influencer Field (#5660)
* [New] Multiple Machine Learning Alerts by Influencer Field

This rule uses alerts data to determine when multiple different machine learning alerts involving the same influencer field are triggered. Analysts can use this to prioritize triage and response, as these entities are more likely to be more suspicious.

* Update multiple_machine_learning_jobs_by_entity.toml

* Update multiple_machine_learning_jobs_by_entity.toml

* Update non-ecs-schema.json

* Update multiple_machine_learning_jobs_by_entity.toml

* Update non-ecs-schema.json

(cherry picked from commit 362c459094)
2026-02-04 12:30:01 +00:00
Ruben Groenewoud 498b8abfd3 [Rule Tuning] Full Kubernetes Ruleset (#5659)
* [Rule Tuning] Full Kubernetes Ruleset

* ++

* Update manifests & schemas

* Update pyproject.toml

* Added "kubernetes.audit.userAgent" to non_ecs

* Updated kubernetes.audit.requestObject.spec.containers.image of type text to Keyword

* Apply suggestion from @Aegrah

* Apply suggestion from @Aegrah

* Update privilege_escalation_pod_created_with_hostnetwork.toml

* Apply suggestion from @Aegrah

* Update privilege_escalation_pod_created_with_hostipc.toml

* Apply suggestion from @Mikaayenson

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* ++

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit c455d3d98a)
2026-02-04 09:46:32 +00:00
github-actions[bot] 959c809be4 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5639)
(cherry picked from commit 8b8c0beec7)
2026-01-28 13:11:26 +00:00
Eric Forte 191f7906a7 Test remote_cli update test indices
(cherry picked from commit 070b457659)
2026-01-27 14:42:07 +00:00
Eric Forte 53f553fe74 [Rule Tuning] Accepted Default Telnet Port Connection (#5629)
* Add Additional Data Sources

(cherry picked from commit 7ff19b3497)
2026-01-27 01:47:12 +00:00
Samirbous 3c4d6b6d83 [New] Multiple Alerts on a Host Exhibiting CPU Spike (#5621)
* [New] Multiple Alerts on a Host Exhibiting CPU Spike

This rule correlates multiple security alerts from a host exhibiting unusually high CPU utilization within a short time window. This behavior may indicate malicious activity such as malware execution, cryptomining, exploit payload execution, or abuse of system resources following initial compromise.

* Update multiple_alerts_on_host_with_cpu_spike.toml

* Rename multiple_alerts_on_host_with_cpu_spike.toml to impact_alerts_on_host_with_cpu_spike.toml

* Update impact_alerts_on_host_with_cpu_spike.toml

* Update rules/cross-platform/impact_alerts_on_host_with_cpu_spike.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update non-ecs-schema.json

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit 42e7f3b4ce)
2026-01-26 20:45:59 +00:00
Samirbous 05aee52726 [New] Detection Alert on a Process Exhibiting CPU Spike (#5617)
* [New] Detection Alert on a Process Exhibiting CPU Spike

This rule correlates security alerts with processes exhibiting unusually high CPU utilization on the same host and process ID within a short time window. This behavior may indicate malicious activity such as malware execution, cryptomining, exploit payload execution, or abuse of system resources following initial compromise.

* Update securityt_alert_from_a_process_with_cpu_spike.toml

* Update securityt_alert_from_a_process_with_cpu_spike.toml

* Update rules/cross-platform/securityt_alert_from_a_process_with_cpu_spike.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Rename securityt_alert_from_a_process_with_cpu_spike.toml to security_alert_from_a_process_with_cpu_spike.toml

* Update security_alert_from_a_process_with_cpu_spike.toml

* Rename security_alert_from_a_process_with_cpu_spike.toml to impact_alert_from_a_process_with_cpu_spike.toml

* Update impact_alert_from_a_process_with_cpu_spike.toml

* Update non-ecs-schema.json

* Update rules/cross-platform/impact_alert_from_a_process_with_cpu_spike.toml

Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>

(cherry picked from commit 094f907144)
2026-01-26 17:46:15 +00:00
Samirbous f1b0b1be5d [New] Multiple Vulnerabilities by Asset via Wiz (#5598)
* [New] Wiz - Multiple Vulnerabilities by Container

* Update multiple_vulnerabilities_wiz_by_container.toml

* Update multiple_vulnerabilities_wiz_by_container.toml

* add wiz manif and schema

* Update multiple_vulnerabilities_wiz_by_container.toml

* Update multiple_vulnerabilities_wiz_by_container.toml

* Update pyproject.toml

* Update multiple_vulnerabilities_wiz_by_container.toml

* ++

* Update external_alerts.toml

* Update multiple_vulnerabilities_wiz_by_container.toml

* Delete detection_rules/etc/integration-manifests.json.gz

* Revert "add wiz manif and schema"

This reverts commit a1e9e7440d.

* Revert "Update pyproject.toml"

This reverts commit 47ab9d2dc8.

* update manifest and schema for wiz

(cherry picked from commit 6d9eef48b0)
2026-01-26 17:30:13 +00:00
Ruben Groenewoud ff4d05b3aa [New/Tuning] General API Abuse D4C/K8s Rules (#5591)
* [New/Tuning] General API Abuse D4C/K8s Rules

* [New Rule] DNS Enumeration Detected via Defend for Containers

* [New Rule] Tool Enumeration Detected via Defend for Containers

* [New Rule] Tool Installation Detected via Defend for Containers

* Service Account File Reads

* [New Rule] Direct Interactive Kubernetes API Request Detected via Defend for Containers

* Rule name update

* [New Rules] D4C K8S MDA API Request Rules

* Add 'tor' to the list of allowed process args

* ++

* ++

* Update rules/integrations/kubernetes/execution_user_exec_to_pod.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update description

* Update rules/integrations/cloud_defend/execution_tool_installation.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update rules/integrations/cloud_defend/execution_tool_installation.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update rules/integrations/cloud_defend/execution_tool_installation.toml

* Update non-ecs-schema.json

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

(cherry picked from commit c5b64c9fbf)
2026-01-26 16:03:31 +00:00
Ruben Groenewoud f8ef14734a [New Rules] Reintroduction of Defend for Containers (D4C) Ruleset (#5561)
* [New Rules] Reintroduction of Defend for Containers (D4C) Ruleset

* ++

* Removed Reintroduced Rules from Deprecated Folder

* Updated Rule Names

* Added maturity field

* [Update] Large D4C Compatibility Overhaul

* Added busybox

* Remove file that was accidently added in this PR

* Creation date revert

* ++

* Update pyproject.toml

* ++

* ++

* Update

* Update schemas/manifests

* ++

(cherry picked from commit fe4418d7f5)
2026-01-26 15:41:51 +00:00
Mika Ayenson, PhD 9b69bc806e Revert "[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578)" (#5620)
This reverts commit c608b673bf.

(cherry picked from commit bbe83452b4)
2026-01-26 14:35:43 +00:00
Ruben Groenewoud 625b6bc531 [Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578)
* [Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules

* Update manifests & schemas

* [New/Updated] Migrated `process.command_line` --> `process.args` for Compatibility

* Pyproject.toml Patch

* ++

(cherry picked from commit c608b673bf)
2026-01-26 12:31:59 +00:00
github-actions[bot] 944093dcd1 Lock versions for releases: 8.19,9.1,9.2,9.3 (#5553)
(cherry picked from commit e5291f455c)
2026-01-12 18:26:13 +00:00
shashank-elastic 9b2b1303ce Prep for Release 9.3 (#5548)
Removed changes from:
- detection_rules/etc/packages.yaml

(selectively cherry picked from commit 1ce072a4e5)
2026-01-12 15:41:28 +00:00
Samirbous 7c36743ce6 [New] Multiple Alerts in Same ATT&CK Tactic by Host (#5550)
* [New] Multiple Alerts in Same ATT&CK Tactic by Host

This rule uses alert data to determine when multiple alerts in the same phase of an attack involving the same host are triggered. Analysts can use this to prioritize triage and response, as these hosts are more likely to be compromised.

* Update multiple_alerts_same_tactic_by_host.toml

* Update rules/cross-platform/multiple_alerts_same_tactic_by_host.toml

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>

* Update non-ecs-schema.json

* Update multiple_alerts_same_tactic_by_host.toml

---------

Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
2026-01-12 14:19:51 +00:00
Ruben Groenewoud 34daf12d51 [New Rules] Several GitHub Related Rules (#5470)
* [New Rules] Several GitHub Related Rules

* Added additional references

* Update defense_evasion_secret_scanning_disabled.toml

* Update persistence_new_pat_created.toml

* Added two more rules

* ++

* Update rules/integrations/github/impact_github_repository_activity_from_unusual_ip.toml

* Added github.repository_public to non_ecs

* Update impact_github_repository_activity_from_unusual_ip.toml

* Update rules/integrations/github/impact_high_number_of_failed_protected_branch_force_pushes_by_user.toml

* ++

* Update rules/integrations/github/exfiltration_high_number_of_cloning_by_user.toml

* Update rules/integrations/github/impact_high_number_of_closed_pull_requests_by_user.toml

* Update rules/integrations/github/impact_high_number_of_protected_branch_force_pushes_by_user.toml

* ++

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
2026-01-08 17:19:12 +01:00
Samirbous 30883ab9c0 [New] React2Shell Network Security Alert (#5445)
* [New] React2Shell Network Security Alert

KQL query that reports network security signatures for React2Shell from 4 integrations (Suricata, Fortigate, Cisco FTD and PANW).

* Update initial_access_react_server_rce_network_alerts.toml

* cisco_ftd schema

 build-schemas -i cisco_ftd

* Update initial_access_react_server_rce_network_alerts.toml

* Update pyproject.toml

* Update rules/network/initial_access_react_server_rce_network_alerts.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update pyproject.toml

* Revert "cisco_ftd schema"

This reverts commit c97cf58b21.

* cisco_ftd schema and manifest

* Update pyproject.toml

* Revert "cisco_ftd schema and manifest"

This reverts commit ff2200f70f.

* Revert "Update pyproject.toml"

This reverts commit d382fcdaaa.

* Reapply "cisco_ftd schema"

This reverts commit 1494d4aa3e.

* Revert "Update pyproject.toml"

This reverts commit 39e1f5e9e3.

* Revert "cisco_ftd schema"

This reverts commit c97cf58b21.

* ++

* Update pyproject.toml

* integration_cisco_ftd

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
2025-12-19 12:22:44 +00:00