Skip to content

Conversation

@Samirbous
Copy link
Contributor

Issues

Resolves #213

Summary

Contributor checklist

@Samirbous Samirbous added v7.10.0 Rule: New Proposal for new rule OS: Windows windows related rules labels Aug 24, 2020
@Samirbous Samirbous self-assigned this Aug 24, 2020
Samirbous and others added 5 commits August 27, 2020 09:14
…_process.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…_process.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…_process.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Copy link
Contributor

@brokensound77 brokensound77 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

few comments then LGTM

…_process.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Copy link
Contributor

@threat-punter threat-punter left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Made some minor suggestions for your review.

Samirbous and others added 2 commits September 17, 2020 23:04
…_process.toml

Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
…_process.toml

Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
@Samirbous Samirbous merged commit d43f814 into main Sep 22, 2020
@Samirbous Samirbous deleted the Process-Masquerading-As-Elastic-Endpoint branch September 22, 2020 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OS: Windows windows related rules Rule: New Proposal for new rule v7.10.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[New Rule] Suspicious Elastic Endpoint Parent Process

4 participants