Prod 1.0.116 updates (#111)

This commit is contained in:
shashank-elastic
2026-05-08 10:27:50 +05:30
committed by GitHub
parent 5d716fbaf5
commit 75c1fd98ed
+54 -21
View File
@@ -20,36 +20,69 @@ Another example of our commitment to openness in security is our existing public
| artifact | version | hash |
| -------------------- | -------------- | --------------- |
| production-rules-linux-v1 | 1.0.115 | 987cb885b57385b684aa4eb40d07e9407a43ece9a08df3ab776a3112457669bd |
| production-rules-macos-v1 | 1.0.115 | f4c8739efafae8e932b7c8c5fb38ec9a86e3f9703212326abecae89acedade14 |
| production-rules-windows-v1 | 1.0.115 | 7df2a890c948179bb6033c4c91c15cf462414bf17237040df1316b8e417124b3 |
| production-rules-linux-v1 | 1.0.116 | 747950d177366c895a1838367edc8d8d2f561f247e525b53951155ed51b17606 |
| production-rules-macos-v1 | 1.0.116 | 36144bb816c83837a119037dbf6c545f156d927084557d3349f94bf3f336c18f |
| production-rules-windows-v1 | 1.0.116 | fa308473d6ba76361a032b416de7aacff44766a2e2bba67a2a3e9d8cc3e91cc5 |
### Rules Summary per Tactic
Note: New Production Rules since last version ('1.0.115', '1.0.114') by OS/MITRE Tactic.
Note: New Production Rules since last version ('1.0.116', '1.0.115') by OS/MITRE Tactic.
| Tactic | Windows | Linux | macOS | Total by Tactic |
|---------------------|-----------|---------|---------|-------------------|
| Command and Control | 1 | 0 | 0 | 1 |
| Defense Evasion | 0 | 1 | 0 | 1 |
| Execution | 1 | 1 | 1 | 3 |
| Persistence | 1 | 0 | 1 | 2 |
| Total by OS | 3 | 2 | 2 | 7 |
| Tactic | Windows | Linux | macOS | Total by Tactic |
|----------------------|-----------|---------|---------|-------------------|
| Collection | 0 | 1 | 0 | 1 |
| Command and Control | 0 | 5 | 0 | 5 |
| Defense Evasion | 0 | 7 | 0 | 7 |
| Discovery | 0 | 1 | 1 | 2 |
| Execution | 0 | 4 | 1 | 5 |
| Initial Access | 0 | 2 | 0 | 2 |
| Persistence | 0 | 4 | 0 | 4 |
| Privilege Escalation | 0 | 1 | 0 | 1 |
| Total by OS | 0 | 25 | 2 | 27 |
Note: Latest Total Production Rules by OS/MITRE Tactic.
| Tactic | Windows | Linux | macOS | Total by Tactic |
|----------------------|-----------|---------|---------|-------------------|
| Collection | 12 | 0 | 8 | 20 |
| Command and Control | 40 | 11 | 41 | 92 |
| Credential Access | 52 | 7 | 35 | 94 |
| Defense Evasion | 322 | 48 | 61 | 431 |
| Discovery | 20 | 1 | 1 | 22 |
| Execution | 95 | 59 | 105 | 259 |
| Collection | 12 | 1 | 8 | 21 |
| Command and Control | 40 | 16 | 41 | 97 |
| Credential Access | 53 | 7 | 35 | 95 |
| Defense Evasion | 322 | 55 | 61 | 438 |
| Discovery | 20 | 2 | 2 | 24 |
| Execution | 97 | 63 | 106 | 266 |
| Exfiltration | 0 | 0 | 2 | 2 |
| Impact | 19 | 6 | 2 | 27 |
| Initial Access | 62 | 1 | 2 | 65 |
| Initial Access | 62 | 3 | 2 | 67 |
| Lateral Movement | 10 | 2 | 1 | 13 |
| Persistence | 61 | 26 | 21 | 108 |
| Privilege Escalation | 73 | 14 | 9 | 96 |
| Total by OS | 766 | 175 | 288 | 1229 |
| Persistence | 61 | 30 | 21 | 112 |
| Privilege Escalation | 75 | 16 | 9 | 100 |
| Total by OS | 771 | 201 | 290 | 1262 |
### MITRE ATT&CK Coverage
#### XDR MITRE scorecard (endpoint + endpoint-scoped SIEM)
- Catalog: 61 parent techniques (Win/Linux/macOS under 8 scorecard tactics)
- Covered (union): 49/61 (80.33%) — production endpoint rules plus production SIEM rules with metadata.integration including "endpoint" and/or index matching logs-endpoint.events* / logs-endpoint.alerts*
- Techniques — endpoint-only: 1, SIEM-only: 5, both: 43
- Rules — production endpoint: 1231, SIEM (in-scope + MITRE): 991
#### Uncovered scorecard techniques (12 distinct parents; listed under each tactic where ATT&CK places them)
- Execution
- T1674 Input Injection
- Persistence
- T1668 Exclusive Control
- T1653 Power Settings
- Defense Evasion
- T1622 Debugger Evasion
- T1678 Delay Execution
- T1480 Execution Guardrails
- T1207 Rogue Domain Controller
- T1679 Selective Exclusion
- T1221 Template Injection
- Credential Access
- T1111 Multi-Factor Authentication Interception
- Impact
- T1561 Disk Wipe
- T1529 System Shutdown/Reboot