mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
327d15a1b5
* [New] PANW Command and Control Correlation
This detection correlates Palo Alto Networks (PANW) command and control events with Elastic Defend network events to identify the source process performing the network activity.
* Update rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Update rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Update rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Update rules/cross-platform/command_and_control_pan_elastic_defend_c2.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Update command_and_control_pan_elastic_defend_c2.toml
* Update command_and_control_pan_elastic_defend_c2.toml
---------
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
(cherry picked from commit 8577bf47b7)