mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
98b8abec19
* [New/Tuning] TeamPCP Simulation - New & Tuned Rules
* ++
* ++
* Added IGs
* Update event action conditions in TOML rule
Refactor process event conditions for clarity.
* Add cloud-related file access patterns to rules
* Update persistence_suspicious_webserver_child_process_execution.toml
* Update rules/integrations/cloud_defend/defense_evasion_file_creation_execution_deletion_cradle.toml
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
* Update defense_evasion_file_creation_execution_deletion_cradle.toml
* Update defense_evasion_file_creation_execution_deletion_cradle.toml
---------
Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>
Removed changes from:
- rules/cross-platform/execution_d4c_k8s_mda_kubernetes_api_activity_by_unusual_utilities.toml
- rules/integrations/cloud_defend/defense_evasion_potential_evasion_via_encoded_payload.toml
- rules/integrations/cloud_defend/execution_payload_downloaded_and_piped_to_shell.toml
- rules/integrations/cloud_defend/execution_suspicious_file_made_executable_via_chmod_inside_a_container.toml
- rules/integrations/cloud_defend/execution_suspicious_interactive_interpreter_command_execution.toml
- rules/integrations/cloud_defend/execution_tool_installation.toml
- rules/integrations/cloud_defend/persistence_suspicious_echo_or_printf_execution.toml
- rules/integrations/cloud_defend/persistence_suspicious_webserver_child_process_execution.toml
(selectively cherry picked from commit 39cdb3887f)