Eric Forte
8981fe73d8
[Rule Tuning] Abnormally Large DNS Response ( #5922 )
...
* Refine event dataset and remove flag on connection type
(cherry picked from commit b2e4925c7f )
2026-04-20 13:31:13 +00:00
Terrance DeJesus
906c43891c
[Rule Tuning] Change event.dataset to data_stream.dataset ( #5943 )
...
* [Rule Tuning] Change event.dataset to data_stream.dataset
* updating ESQL field names
Removed changes from:
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/initial_access_elastic_defend_alert_genai_utility_descendant.toml
- rules/cross-platform/initial_access_elastic_defend_alert_package_manager_ancestor.toml
- rules/cross-platform/multiple_alerts_llm_compromised_user_triage.toml
- rules/cross-platform/multiple_elastic_defend_behavior_rules_same_host_prevalence.toml
(selectively cherry picked from commit deab1c0161 )
2026-04-10 16:31:06 +00:00
Mika Ayenson, PhD
44f69a586b
[Rule Tuning] Add Supplemental Mitre Mappings ( #5876 )
...
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
Co-authored-by: eric-forte-elastic <eric.forte@elastic.co >
Removed changes from:
- rules/cross-platform/command_and_control_kubectl_networking_modification.toml
- rules/cross-platform/defense_evasion_potential_kubectl_impersonation.toml
- rules/cross-platform/defense_evasion_potential_kubectl_masquerading.toml
- rules/cross-platform/discovery_kubectl_permission_discovery.toml
- rules/cross-platform/execution_d4c_k8s_mda_direct_interactive_kubernetes_api_request_by_usual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_forbidden_direct_interactive_kubernetes_api_request.toml
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/cross-platform/execution_d4c_k8s_mda_service_account_token_access_followed_by_kubernetes_api_request.toml
- rules/cross-platform/execution_kubernetes_direct_api_request_via_curl_or_wget.toml
- rules/integrations/azure/ml_azure_rare_method_by_city.toml
- rules/integrations/azure/ml_azure_rare_method_by_country.toml
- rules/integrations/azure/ml_azure_rare_method_by_user.toml
- rules/integrations/cloud_defend/command_and_control_curl_socks_proxy_detected_inside_container.toml
- rules/integrations/cloud_defend/command_and_control_interactive_file_download_from_internet.toml
- rules/integrations/cloud_defend/command_and_control_tunneling_and_port_forwarding.toml
- rules/integrations/cloud_defend/credential_access_cloud_creds_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_collection_sensitive_files_compression_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_sensitive_keys_or_passwords_search_inside_a_container.toml
- rules/integrations/cloud_defend/credential_access_service_account_token_or_cert_read.toml
- rules/integrations/cloud_defend/defense_evasion_decoded_payload_piped_to_interpreter.toml
- rules/integrations/cloud_defend/defense_evasion_file_creation_execution_deletion_cradle.toml
- rules/integrations/cloud_defend/defense_evasion_interactive_process_execution_from_suspicious_directory.toml
- rules/integrations/cloud_defend/defense_evasion_ld_preload_shared_object_modified_inside_a_container.toml
- rules/integrations/cloud_defend/defense_evasion_potential_evasion_via_encoded_payload.toml
- rules/integrations/cloud_defend/discovery_dns_enumeration.toml
- rules/integrations/cloud_defend/discovery_environment_enumeration.toml
- rules/integrations/cloud_defend/discovery_kubelet_certificate_file_access.toml
- rules/integrations/cloud_defend/discovery_kubelet_pod_discovery_via_builtin_utilities.toml
- rules/integrations/cloud_defend/discovery_privilege_boundary_enumeration_from_interactive_process.toml
- rules/integrations/cloud_defend/discovery_service_account_namespace_read.toml
- rules/integrations/cloud_defend/discovery_suspicious_network_tool_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_container_management_binary_launched_inside_a_container.toml
- rules/integrations/cloud_defend/execution_direct_interactive_kubernetes_api_request.toml
- rules/integrations/cloud_defend/execution_interactive_file_creation_in_system_binary_locations.toml
- rules/integrations/cloud_defend/execution_kubeletctl_execution.toml
- rules/integrations/cloud_defend/execution_netcat_listener_established_inside_a_container.toml
- rules/integrations/cloud_defend/execution_payload_downloaded_and_piped_to_shell.toml
- rules/integrations/cloud_defend/execution_potential_direct_kubelet_access_via_process_args.toml
- rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml
- rules/integrations/cloud_defend/execution_suspicious_interactive_interpreter_command_execution.toml
- rules/integrations/cloud_defend/execution_tool_installation.toml
- rules/integrations/cloud_defend/persistence_modification_of_persistence_relevant_files.toml
- rules/integrations/cloud_defend/persistence_ssh_authorized_keys_modification_inside_a_container.toml
- rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml
- rules/integrations/cloud_defend/privilege_escalation_debugfs_launched_inside_a_privileged_container.toml
- rules/integrations/cloud_defend/privilege_escalation_potential_container_escape_via_modified_release_agent_file.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_city.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_country.toml
- rules/integrations/gcp/ml_gcp_rare_method_by_user.toml
- rules/linux/discovery_docker_socket_discovery.toml
- rules/linux/discovery_kubeconfig_file_discovery.toml
- rules/linux/execution_kubectl_apply_pod_from_url.toml
- rules/linux/lateral_movement_kubeconfig_file_activity.toml
- rules/linux/persistence_kubernetes_sensitive_file_activity.toml
- rules_building_block/discovery_kubectl_workload_and_cluster_discovery.toml
(selectively cherry picked from commit 8993d1450b )
2026-04-01 14:15:58 +00:00
Eric Forte
79988e3bc5
Do not fire on denied events ( #5805 )
...
(cherry picked from commit a9f3f8afbb )
2026-03-04 19:08:56 +00:00
Eric Forte
db2299beb4
Tuning to allow for greater flexibility in integration policy ( #5774 )
...
(cherry picked from commit b2f76bd2c9 )
2026-02-25 18:59:21 +00:00
Eric Forte
499c29e1af
[Rule Tuning] Accepted Default Telnet Port Connection ( #5737 )
...
* Remove event type end from results
(cherry picked from commit 4278521811 )
2026-02-19 20:19:46 +00:00
Terrance DeJesus
6e3c0ada14
[New Rule] Fortigate (FG-IR-26-060) Detections ( #5641 )
...
* initial FG-IR-26-060 rules
* adjusted investigation guides to proper formatting
* Update initial_access_fortigate_sso_login_from_unusual_source.toml
* Update and rename exfiltration_fortigate_config_download.toml to collection_fortigate_config_download.toml
* Update collection_fortigate_config_download.toml
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* adjusting rules
* revert super admin
* adjusted source.ip to 'fortinet.firewall.ui'
* changing ESQL to EQL for non-aggregate queries
* added CISA reference
* adjusted interval and maxspan
* updating dates
* changed download rule to EQL
* added additional sso checks; linted previous rules
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
(cherry picked from commit ae88c095e9 )
2026-01-30 15:19:32 +00:00
Samirbous
4fed99a667
[New] Suspicious FortiGate and Fortinet Logon rules ( #5640 )
...
* [New] Suspicious FortiGate Admin Logon rules
- First-Time FortiGate Administrator Login
- FortiGate Administrator Login from Multiple IP Addresses
* Update initial_access_fortigate_admin_login_multi_srcip.toml
* ++
* ++
* Create initial_access_newly_observed_frotinet_logon.toml
* Update initial_access_newly_observed_frotinet_logon.toml
* build schema and manifest for fortinet
* Update pyproject.toml
* Update initial_access_newly_observed_frotinet_logon.toml
* Revert "Update initial_access_newly_observed_frotinet_logon.toml"
This reverts commit 7b99828b9a .
* Revert "Update pyproject.toml"
This reverts commit 025daf566f .
* Revert "build schema and manifest for fortinet"
This reverts commit a6234164f8 .
* ++
(cherry picked from commit a2c1dd8575 )
2026-01-28 18:00:25 +00:00
Eric Forte
fa89777a63
[Rule Tuning] Accepted Default Telnet Port Connection ( #5629 )
...
* Add Additional Data Sources
(cherry picked from commit 7ff19b3497 )
2026-01-27 01:46:26 +00:00
Jonhnathan
7d1d43ad21
Update discovery_potential_port_scan_detected.toml ( #5571 )
...
(cherry picked from commit 58b0d8e553 )
2026-01-17 02:24:07 +00:00
Samirbous
148f9aa25f
[Tuning] SMB (Windows File Sharing) Activity to the Internet ( #5533 )
...
* [Tuning] SMB (Windows File Sharing) Activity to the Internet
converted to new term (history search window set to 5 days by destination.ip) to reduce alerts volume. https://github.com/elastic/detection-rules/issues/5490
* Update initial_access_smb_windows_file_sharing_activity_to_the_internet.toml
* Update rules/network/initial_access_smb_windows_file_sharing_activity_to_the_internet.toml
* Update rules/network/initial_access_smb_windows_file_sharing_activity_to_the_internet.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit e7cb01778b )
2026-01-08 21:56:08 +00:00
Jonhnathan
11b1cd98a7
[Rule Tuning] Potential Network Scan Detected ( #5495 )
...
* [Rule Tuning] Potential Network Scan Detected
* Update discovery_potential_port_scan_detected.toml
* Update rules/network/discovery_potential_port_scan_detected.toml
* ++
* Update discovery_potential_port_scan_detected.toml
* Update discovery_potential_port_scan_detected.toml
(cherry picked from commit 1d64bf0d76 )
2025-12-19 15:42:43 +00:00
Samirbous
7d21dbe9fc
[New] React2Shell Network Security Alert ( #5445 )
...
* [New] React2Shell Network Security Alert
KQL query that reports network security signatures for React2Shell from 4 integrations (Suricata, Fortigate, Cisco FTD and PANW).
* Update initial_access_react_server_rce_network_alerts.toml
* cisco_ftd schema
build-schemas -i cisco_ftd
* Update initial_access_react_server_rce_network_alerts.toml
* Update pyproject.toml
* Update rules/network/initial_access_react_server_rce_network_alerts.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* Update pyproject.toml
* Revert "cisco_ftd schema"
This reverts commit c97cf58b21 .
* cisco_ftd schema and manifest
* Update pyproject.toml
* Revert "cisco_ftd schema and manifest"
This reverts commit ff2200f70f .
* Revert "Update pyproject.toml"
This reverts commit d382fcdaaa .
* Reapply "cisco_ftd schema"
This reverts commit 1494d4aa3e .
* Revert "Update pyproject.toml"
This reverts commit 39e1f5e9e3 .
* Revert "cisco_ftd schema"
This reverts commit c97cf58b21 .
* ++
* Update pyproject.toml
* integration_cisco_ftd
---------
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 30883ab9c0 )
2025-12-19 12:26:37 +00:00
Terrance DeJesus
05704938ca
[New Rule] React2Shell Detection ( #5408 )
...
* [New Rule] BBR - Potential React.JS CVE-2025-55182 Exploit Attempt
Fixes #5406
* updated descriptions
* changed to EQL
* adjusted note
* Update rules_building_block/initial_access_react_server_components_rce_attempt.toml
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
* adjusted query
* adding anomalous RSC BBR rule; adusted query to be react2shell RCE specific
* updated BBR
* removed BBR react2shell rule
* adjusted regex to not be proto focused
* Update rules/network/initial_access_react_server_components_rce_attempt.toml
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
* adjusted query
* removed constructor requirement
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com >
Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com >
(cherry picked from commit 0b949910a5 )
2025-12-05 23:41:41 +00:00
Jonhnathan
d3aa4b2f38
[Rule Tuning] Reduce Severity from Critical to High ( #4637 )
2025-05-06 21:37:47 +05:30
shashank-elastic
e4856d3c2c
Refresh ecs, beats, integration manifests & schemas ( #4699 )
2025-05-05 23:06:40 +05:30
Jonhnathan
5653190d08
[Rule Tuning] Remove hardcoded logic from description ( #4503 )
2025-02-28 14:38:18 -03:00
Ruben Groenewoud
32975e5155
[Rule Tuning] Port Scan Rules ( #4443 )
2025-02-05 15:40:27 +01:00
Mika Ayenson
fe8c81d762
[FR] Generate investigation guides ( #4358 )
2025-01-22 11:17:38 -06:00
Samirbous
65b95a1996
Update discovery_potential_syn_port_scan_detected.toml ( #4366 )
2025-01-10 15:29:29 +00:00
Samirbous
5e0fb4a63e
[Tuning] Add logs-panw.panos index to Network rules ( #4089 )
...
* [Tuning] Add logs-panw.panos index to Network rules
https://github.com/elastic/detection-rules/issues/3998
This PR adds to the PANOS traffic index `.ds-logs-panw.panos-default-*` to the network rules using fields that are compatible.
* add tag and integration
* Update command_and_control_fin7_c2_behavior.toml
* Build Manifest and Schema for panw integration
* Update definitions.py
* Update definitions.py
* Fix definitions declaration
---------
Co-authored-by: Shashank K S <Shashank.Suryanarayana@elastic.co >
2024-09-19 08:01:44 +01:00
Jonhnathan
f5069763b6
[Rule Tuning] Add System tag to DRs ( #3968 )
...
* [Rule Tuning] Add System tag to DRs
* bump
2024-08-09 11:14:33 -03:00
Jonhnathan
fbaac66f9f
[Rule Tuning] Accepted Default Telnet Port Connection ( #3954 )
...
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2024-08-03 20:15:06 -03:00
shashank-elastic
63e91c2f12
Back-porting Version Trimming ( #3704 )
2024-05-23 00:45:10 +05:30
Mika Ayenson
2c3dbfc039
Revert "Back-porting Version Trimming ( #3681 )"
...
This reverts commit 71d2c59b5c .
2024-05-22 13:51:46 -05:00
shashank-elastic
71d2c59b5c
Back-porting Version Trimming ( #3681 )
2024-05-23 00:11:50 +05:30
Mika Ayenson
07abc19932
[Rule Tuning] SMTP on Port 26/TCP ( #3521 )
2024-03-19 15:55:25 -05:00
Terrance DeJesus
1c10c37468
[Rule Tuning] Update timestamp_override Unit Tests and Fix Rules Missing Field ( #3368 )
...
* updated timestamp override unit test; fixed rules missing this field
* fixed flake error
* simplified and consolidated logic
* Update tests/test_all_rules.py
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
* Update tests/test_all_rules.py
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
* added comments
* updated logic; added comments; removed unused variables
* removed custom python script
* updated dates
* removed deprecated rule change
* updated dates
---------
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2024-01-17 14:14:38 -05:00
Eric
a4ad0b6a24
Fix syntax error in query ( #3285 )
...
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2023-12-07 07:49:18 -03:00
Ruben Groenewoud
020fff3aea
[Rule Tuning] Linux Rules ( #3092 )
...
* [Rule Tuning] [WIP] Linux DR
* Update defense_evasion_binary_copied_to_suspicious_directory.toml
* Fixed tag
* Added additional tuning
* unit test fix
* Additional tuning
* tuning
* added max signals
* Added max_signals=1 to brute force rules
* Cross-Platform Tuning
* Small fix
* new_terms conversion
* typo
* new_terms conversion
* Ransomware rule tuning
* performance tuning
* new_terms conversion for auditd_manager
* tune
* Need coffee
* kql/eql stuff
* formatting improvement
* new_terms sudo hijacking conversion
* exclusion
* Deprecations that were added last tuning
* Deprecations that were added last tuning
* Increased max timespan for brute force rules
* version bump
* added domain tag
* Two tunings
* More tuning
* Additional tuning
* updated_date bump
* query optimization
* Tuning
* Readded the exclusions for this one
* Changed int comparison
* Some tunings
* Update persistence_systemd_scheduled_timer_created.toml
* Update rules/linux/privilege_escalation_ld_preload_shared_object_modif.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* [New Rule] Potential curl CVE-2023-38545 Exploitation
* Revert "[New Rule] Potential curl CVE-2023-38545 Exploitation"
This reverts commit 9c04d1b53d .
* Update rules/cross-platform/command_and_control_non_standard_ssh_port.toml
* Update rules/linux/command_and_control_cat_network_activity.toml
* Update persistence_message_of_the_day_execution.toml
* Changed max_signals
* Revert "Merge branch 'main' into rule-tuning-ongoing-dr"
This reverts commit 1106b5d2eb , reversing
changes made to 5ff510757f .
* Revertable merge
* Update defense_evasion_ld_preload_env_variable_process_injection.toml
* File name change
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2023-10-23 16:28:58 +02:00
Jonhnathan
82685e36ce
[Rule Tuning] Adjust Lucene queries to use Uppercase operators ( #3196 )
2023-10-16 17:07:53 -03:00
Terrance DeJesus
b8ae2218f8
[Rule Tuning] Add filebeat Compatibility to Network Rules ( #2925 )
...
* add beats compatability to NPC rules
* added filebeat compatibility to 'Accepted Default Telnet Port Connection'
* added filebeat compatibility to 'Cobalt Strike Command and Control Beacon'
* added filebeat compatibility to 'Default Cobalt Strike Team Server Certificate'
* added filebeat compatibility to 'Roshal Archive (RAR) or PowerShell File Downloaded from the Internet'
* added filebeat compatibility to 'Possible FIN7 DGA Command and Control Behavior'
* added filebeat compatibility to 'Halfbaked Command and Control Beacon'
* added filebeat compatibility to 'IPSEC NAT Traversal Port Activity'
* added filebeat compatibility to 'SMTP on Port 26/TCP'
* added filebeat compatibility to 'RDP (Remote Desktop Protocol) from the Internet'
* added filebeat compatibility to 'VNC (Virtual Network Computing) from the Internet'
* added filebeat compatibility to 'VNC (Virtual Network Computing) to the Internet'
* added filebeat compatibility to 'RPC (Remote Procedure Call) from the Internet'
* added filebeat compatibility to 'RPC (Remote Procedure Call) to the Internet'
* added filebeat compatibility to 'SMB (Windows File Sharing) Activity to the Internet'
* removed extra space in query
* added filebeat compatibility to 'Inbound Connection to an Unsecure Elasticsearch Node'
* added filebeat compatibility to 'Abnormally Large DNS Response'
* fixed missing ending parenthesis
* added auditbeat to compatible rules
* addressed feedback
* removed filebeat and auditbeat due to incompatibility
* Update rules/network/command_and_control_cobalt_strike_beacon.toml
* Update rules/network/command_and_control_accepted_default_telnet_port_connection.toml
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
Co-authored-by: Justin Ibarra <16747370+brokensound77@users.noreply.github.com >
2023-10-03 15:05:41 -04:00
Steve Ross
4f33a40f48
[Bug] Duplicate tag on Okta rule ( #3020 )
...
* Fix double tag on rule
* fixed all rules; added unit test
---------
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2023-08-21 10:42:47 -04:00
Ruben Groenewoud
a7ff449fbc
[Rule Tuning] Some Tunings of several 8.9 rules ( #2985 )
...
* [Rule Tuning] Doing some quick tunings
* updated_date bump
* Update rules/linux/discovery_linux_modprobe_enumeration.toml
* Update rules/linux/discovery_linux_modprobe_enumeration.toml
* Update rules/linux/discovery_linux_sysctl_enumeration.toml
* Update rules/linux/persistence_init_d_file_creation.toml
* Update rules/linux/persistence_rc_script_creation.toml
* Update rules/linux/persistence_shared_object_creation.toml
* deprecate rule
* deprecate rule
* Update execution_abnormal_process_id_file_created.toml
* Update discovery_kernel_module_enumeration_via_proc.toml
* Update discovery_linux_modprobe_enumeration.toml
* Update execution_remote_code_execution_via_postgresql.toml
* Update discovery_potential_syn_port_scan_detected.toml
* Added 2 tunings, sorry I missed those..
* One more tune
* Update discovery_suspicious_proc_enumeration.toml
2023-08-03 15:25:33 +02:00
Remco Sprooten
1283a21fb7
[New Rules] Potential portscan detected ( #2817 )
...
* [New Rules] Potential portscan detected
* Updated descriptions
* Update rules/network/discovery_potential_syn_port_scan_detected.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/network/discovery_potential_network_sweep_detected.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* Update rules/network/discovery_potential_port_scan_detected.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
* updating integration manifests and schemas
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com >
Co-authored-by: terrancedejesus <terrance.dejesus@elastic.co >
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com >
2023-07-09 09:49:32 +02:00
Terrance DeJesus
48cf95c8eb
[Rule Tuning] Change Network Rules to Use Network Packet Capture Integration ( #2665 )
...
* updated indexes and updated dates
* added network_traffic integration tag to rules
* reverting changes to resolve conflicts
* metadata changes; indexes changed; schemas and manifest updated
* updated default telnet port connection rule
* updating integration manifests
* adjusted rules; updated integrations; deduplicate packages
2023-06-26 17:35:49 -04:00
Jonhnathan
b4c84e8a40
[Security Content] Tags Reform ( #2725 )
...
* Update Tags
* Bump updated date separately to be easy to revert if needed
* Update resource_development_ml_linux_anomalous_compiler_activity.toml
* Apply changes from the discussion
* Update persistence_init_d_file_creation.toml
* Update defense_evasion_timestomp_sysmon.toml
* Update defense_evasion_application_removed_from_blocklist_in_google_workspace.toml
* Update missing Tactic tags
* Update unit tests to match new tags
* Add missing IG tags
* Delete okta_threat_detected_by_okta_threatinsight.toml
* Update command_and_control_google_drive_malicious_file_download.toml
* Update persistence_rc_script_creation.toml
* Mass bump
* Update persistence_shell_activity_by_web_server.toml
* .
---------
Co-authored-by: Mika Ayenson <Mika.ayenson@elastic.co >
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2023-06-22 18:38:56 -03:00
Justin Ibarra
59da2da474
[Rule Tuning] Ensure host information is in endpoint rule queries ( #2593 )
...
* add unit tests to ensure host type and platform are included
* add host.os.name 'linux' to all linux rules
* add host.os.name macos to mac rules
* add host.os.name to windows rules; fix linux dates
* update from host.os.name to host.os.type
Co-authored-by: brokensound77 <brokensound77@users.noreply.github.com >
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com >
2023-03-05 11:41:19 -07:00
Terrance DeJesus
4312d8c958
[FR] Add Endpoint, APM and Windows Integration Tags to Rules and Supportability ( #2429 )
...
* initial commit
* addressing flake errors
* added apm to _get_packagted_integrations logic
* addressed flake errors
* adjusted integration schema and updated rules to be a list
* updated several rules and removed a unit test
* updated rules with logs-* only index patterns
* Update tests/test_all_rules.py
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
* addressed flake errors
* integration is none is windows, endpoint or apm
* adding rules with accepted incoming changes from main
* fixed tag and tactic alignment errors from unit testing
* adjusted unit testing logic for integration tags; added more exclusion rules
* adjusted test_integration logic to be rule resistent and skip if -8.3
* adjusted comments for unit test skip
* fixed merge conflicts from main
* changing test_integration_tag to remove logic for rule version comparisons
* added integration tag to new rule
* adjusted rules updated_date value
* ignore guided onboarding rule in unit tests
* added integration tag to new rule
Co-authored-by: Mika Ayenson <Mikaayenson@users.noreply.github.com >
2023-01-04 09:30:07 -05:00
Terrance DeJesus
4997f95300
[Rule Tuning] Link Elastic Security Labs content to compatible rules ( #2388 )
...
* added elastic security labs URL references
* Update rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml
Is not compatible with Windows blog.
* Update rules/macos/credential_access_keychain_pwd_retrieval_security_cmd.toml
Is not compatible with Windows blog. Reverting updated date.
* Update rules/macos/credential_access_access_to_browser_credentials_procargs.toml
Is not compatible with Windows blog. Reverting updated date.
* Update rules/macos/credential_access_access_to_browser_credentials_procargs.toml
Is not compatible with Windows blog.
* Update rules/ml/execution_ml_windows_anomalous_script.toml
Is not compatible with Windows blog. Reverting updated date.
* Update rules/linux/credential_access_collection_sensitive_files.toml
Not compatible with Windows blog. Reverting updated date.
* Update rules/linux/credential_access_collection_sensitive_files.toml
Not compatible with Windows blog.
* added credential access URL for mimikatz rules
* updated version ml windows anomalous script rule
* removed change to macOS rule since no blog correlation
2022-11-07 15:17:49 -05:00
Terrance DeJesus
fd1260c109
[Rule Tuning] Tune "Telnet Port Activity" Rule for Accepted Connections Only ( #2374 )
...
* adjusted query to include event action and network direction filters
* adjusted rule name and file name
* toml linted and tags updated
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2022-11-07 14:00:25 -05:00
Justin Ibarra
46d5e37b76
min_stack all rules to 8.3 ( #2259 )
...
* min_stack all rules to 8.3
* bump date
Co-authored-by: Mika Ayenson <mika.ayenson@elastic.co >
2022-08-24 10:38:49 -06:00
Terrance DeJesus
a76c51ae17
[Deprecation rule] DNS Activity to the Internet ( #2221 )
2022-08-02 20:59:35 -05:00
Mika Ayenson
a52751494e
2058 add setup field to metadata ( #2061 )
...
* Convert config header to setup in note field
* Parse note field into separate setup and note field with marko gfm
* only validate and parse note on elastic authored rules and add CLI description for new DR_BYPASS_NOTE_VALIDATION_AND_PARSE environment variable
Co-authored-by: brokensound77 <brokensound77@users.noreply.github.com >
2022-07-18 15:41:32 -04:00
Terrance DeJesus
93edc44284
[Rule Tuning] Timeline Templates For Windows and Linux ( #1892 )
...
* added comprehensive file timeline to Hosts File Modified rule
* added Comprehensive Process Timeline to Interactive Terminal Spawned via Python rule
* updated rules to have generic instead of comprehensive
* updated several rules with timeline ID and timeline title values
* changed updated_date for threat intel fleet integrations
* added missing templates to timeline_templates dict in definitions.py
* added comprehensive timeline templates to alerts after definitions.py was updated
* updated rules with comprehensive timeline templates and added min stack comments and versions
* removing timeline template changes which is tracked in #1904
* Update rules/linux/execution_python_tty_shell.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
* Delete Pipfile
Removing pipfile
* Delete Pipfile.lock
deleting pipfile.lock
* Update rules/windows/execution_command_shell_started_by_svchost.toml
updating title
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
2022-04-01 13:44:35 -04:00
Jonhnathan
7b0383ffe2
[Rule Tuning] Switch "Roshal Archive (RAR) or PowerShell File Downloaded from the Internet" to use KQL ( #1651 )
...
* Update command_and_control_download_rar_powershell_from_internet.toml
* bump updated_date
2021-12-07 09:09:03 -03:00
Jonhnathan
5e4a7e67df
[Rule Tuning] Small update on rule descriptions ( #1508 )
2021-09-30 12:54:15 -08:00
Justin Ibarra
f8f643041a
[Rule tuning] Revise rule description and other text ( #1398 )
2021-08-03 13:07:47 -08:00
Justin Ibarra
b736d6e748
[Rule Tuning] Rule description tweaks ( #1388 )
2021-07-29 10:56:13 -08:00
Andrew Pease
34df7c6b89
[Rule Tuning] Add Filebeat and Auditbeat to Network Rules ( #1282 )
...
* standardized indices and added the from field
2021-07-20 22:59:22 -08:00