Skip to content

Conversation

Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Sep 16, 2025

Summary

Misc. Linux DR Tunings

@tradebot-elastic
Copy link

tradebot-elastic commented Sep 16, 2025

⛔️ Test failed

Results
  • ❌ AWS CLI Command with Custom Endpoint URL (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Git Repository or File Download to Suspicious Directory (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Curl SOCKS Proxy Activity from Unusual Parent (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Linux Clipboard Activity Detected (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Network Activity Detected via cat (eql)
    • stack_validation_failed: no_alerts - 0 alerts

@tradebot-elastic
Copy link

tradebot-elastic commented Sep 16, 2025

⛔️ Test failed

Results
  • ❌ AWS CLI Command with Custom Endpoint URL (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Git Repository or File Download to Suspicious Directory (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Curl SOCKS Proxy Activity from Unusual Parent (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Linux Clipboard Activity Detected (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Network Activity Detected via cat (eql)
    • stack_validation_failed: no_alerts - 0 alerts

@tradebot-elastic
Copy link

tradebot-elastic commented Sep 16, 2025

⛔️ Test failed

Results
  • ❌ AWS CLI Command with Custom Endpoint URL (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Git Repository or File Download to Suspicious Directory (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Curl SOCKS Proxy Activity from Unusual Parent (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Linux Clipboard Activity Detected (kuery)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Network Activity Detected via cat (eql)
    • stack_validation_failed: no_alerts - 0 alerts

[rule.new_terms]
field = "new_terms_fields"
value = ["host.id", "process.group_leader.executable"]
value = ["host.id", "process.parent.executable"]
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

don't think CS support process.parent.executable as per the Linux EDR matrix, cc @w0rk3r

[rule.new_terms]
field = "new_terms_fields"
value = ["user.name"]
value = ["host.id"]
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not sure if host.id is mapped correctly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants