Releases: elastic/detection-rules
Release list
dev-v2.1.0
Changes
- [FR] Upgrade eql to 1.0.1, align KQL with lark 1.x, and fix NTLM relay field comparison (#6611) @Mikaayenson
- [New Rule] Newly Observed RC4 Kerberos Service Ticket Request (#6587) @w0rk3r
- [New Rule] Repeated Stalled TLS Handshakes via ALPN acme-tls/1 Extension (#6272) @eric-forte-elastic
- [New Rule] First Time Seen RMM Signer Across the Environment (#6522) @w0rk3r
- [New Rule] Azure AKS Service Account Token Created via TokenRequest API (#6422) @terrancedejesus
- [Rule: Tuning] Rule triggers for false positive due to broad wildcard (#6205) @litemars
- [Rule Tuning] Windows Misc Tunings (#6568) @w0rk3r
- [New Rule] Potential NFS Destructive Operation Burst (#6536) @eric-forte-elastic
- [New Rule] Azure AKS Certificate Signing Request Created or Approved (#6420) @terrancedejesus
- [New Rule] Potential EDR-Freeze via WerFaultSecure Abuse (#6248) @Aryu-RU
- [Deprecation] Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt (#6567) @Aegrah
- [Rule Tuning] Suspicious Service was Installed in the System (#6523) @w0rk3r
- [New Rule] Suspicious UID Change to Root via Python (#6566) @Aegrah
- [Rule Tuning] Wrong regex in the macOS c2 detection query (#6548) @litemars
- [Rule Tuning] Fixing Typo in the macOS persistence emond modification rule (#6529) @litemars
- [Rule: Tuning] Fixing logic issue on the macOS rule for discovery external IP using curl (#6530) @litemars
- [New Rule] Direct Process Execution via setsid, nohup, or disown (#6526) @Aegrah
- [New Rule] Azure AKS CoreDNS or Kube-DNS Configuration Modified (#6417) @terrancedejesus
- [New Rule] Azure AKS Secret get or list with Suspicious User Agent (#6421) @terrancedejesus
- [New Rule] NFS AUTH_SYS Root UID Access (#6535) @eric-forte-elastic
- [Rule Tuning] Connection to Commonly Abused Web Services (#6451) @Mikaayenson
- [Rule Tuning] Potential Data Exfiltration Through Curl (#6520) @Mikaayenson
- [New Rule] Mark-of-the-Web Removal by an Unusual Process (#6533) @w0rk3r
- [Rule Tuning] M365 Identity Login from Atypical Region (#6409) @Mikaayenson
- [Rule Tuning] Entra ID User Sign-in with Unusual Client (#6429) @Mikaayenson
- [Rule Tuning] Entra ID High Risk Sign-in (#6408) @Mikaayenson
- [New Rules] GCP GKE Rule Conversions Part 6 (#6482) @imays11
- [New Rule] First Time Seen Memcached Writer (#6534) @eric-forte-elastic
- [New Rule] Destructive MongoDB Command (#6540) @eric-forte-elastic
- [New Rule] MySQL User-Defined Function Injection (#6541) @eric-forte-elastic
- [New Rule] Postgresql COPY PROGRAM Command Execution (#6542) @eric-forte-elastic
- [New Rule] Cassandra JavaScript UDF Creation (#6543) @eric-forte-elastic
- [Rule Tuning] Potential Computer Account NTLM Relay Activity (#6512) @eric-forte-elastic
- [New Rule] Thrift RPC Method from an External Client (#6544) @eric-forte-elastic
- [New Rule] Potential SIP REGISTER Brute Force (#6538) @eric-forte-elastic
- [New Rule] Potential SIP Extension Enumeration (#6539) @eric-forte-elastic
- [New Rule] Successful AMQP Multi-Queue Purge Burst (#6546) @eric-forte-elastic
- [New Rule] Multiple SonicWall Login Failures Followed by Successful Login (#6514) @eric-forte-elastic
- [New Rule] AWS Bedrock High Risk Filesystem or Execution Tool Invocation (#6510) @bryans3c
- [New Rule] AWS Batch Job Submitted with Container Override by Unusual Identity (#6509) @bryans3c
- [New Rule] AWS IAM Permission Boundary or Guardrail Policy Deleted by Unusual Identity (#6508) @bryans3c
- [New Rule] AWS IAM User Created Own Access Key (#6436) @bryans3c
- [New Rule] AWS SageMaker Execution Role Passed by Unusual Principal (#6435) @bryans3c
- [Rule Tuning] AWS Bedrock High-Frequency Single-Model Inference API Probing (#6411) @bryans3c
- [New Rule] AWS S3 Bucket ACL Modified to Allow Public Access by New Identity (#6507) @bryans3c
- [New Rule] AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity (#6505) @bryans3c
- [Rule Tuning] Misc Windows Tunings (#6513) @w0rk3r
- [New Rule] Unusual File Creation via Web Server (#6496) @Aegrah
- [New Rule] Azure AKS Kubernetes Events Deleted (#6423) @terrancedejesus
- [New Rule] Azure AKS Potential API Enumeration by User (#6424) @terrancedejesus
- [New/Tuning] Potential Tunneling via Tailscaled (#6519) @Aegrah
- [Rule Tuning] Removing
process.interactive == trueEnforcement (#6518) @Aegrah - [Rule Tuning] Higher-Order Multi Att&ck Tactics rules (#6480) @w0rk3r
- [Rule Tuning] Potential Computer Account NTLM Relay Activity (#6431) @Mikaayenson
- [New Rule] Azure AKS Suspicious Self-Subject Review via Service Account (#6425) @terrancedejesus
- [New Rule] Azure AKS Ephemeral Container Added to Pod (#6426) @terrancedejesus
- Update related integrations for ML detection rules (#6497) @sodhikirti07
- [Rule Tuning] Potential Credential Access via DCSync (#6415) @Mikaayenson
- [Rule Tuning] Persistence via Scheduled Job Creation (#6481) @w0rk3r
- [Rule Tuning] Expand Comsvcs MiniDump ordinal coverage (#6489) @django-88
- [Rule Tuning] PHP File Creation in WordPress Plugin Directory (#6485) @Aegrah
- [Rule Tuning] Newly Observed Palo Alto Network Alert (#6477) @eric-forte-elastic
- Wget and curl LLM assisted rules (#6448) @aarju
- [New Rules] GCP GKE Rule Conversions Part 5 (#6466) @imays11
- [Rule Tuning] GenAI Process Connection to Unusual Domain (#6462) @Mikaayenson
- [Rule Tuning] Web Application Suspicious Activity: Unauthorized Method (#6467) @Mikaayenson
- [New Rule] Azure AKS User Exec into Pod (#6427) @terrancedejesus
- [New Rules] GCP GKE Rule Conversions Part 4 (#6456) @imays11
- [Rule Tuning] Suspicious Child Execution via Web Server (#6472) @Mikaayenson
- [New Rules] GCP GKE CSR Abuse Rules (#6405) @imays11
- [New Rules] GCP GKE Rule Conversions Part 3 (#6445) @imays11
- [Rule Tuning] Misc. Linux LPE Rules (#6465) @Aegrah
- [Rule Tuning] Lucene Network Rules Language Conversion (#6463) @eric-forte-elastic
- [Rule Tuning] Web Application Suspicious Activity: POST Request Declined (#6469) @eric-forte-elastic
- [New Rule/Tuning] PHP File Creation in WordPress Plugin Directory (#6473) @Aegrah
🚀 Features
- [FR] Add nested KQL query support in lib/kql (#6492) @imays11
- [FR] Add XDR rule tag taxonomy to Copilot PR review (#6591) @Mikaayenson
- Lock versions for releases: 8.19,9.3,9.4,9.5 (#6569) @github-actions[bot]
- chore: bump setup tools (#6545) @eric-forte-elastic
- [FR] Switch to ephemeral tokens for non DR workflows (#6524) @eric-forte-elastic
- Lock versions for releases: 8.19,9.3,9.4,9.5 (#6478) @github-actions[bot]
- Prep for Release 9.5 (#6474) @shashank-elastic
🐛 Bug Fixes
- [Bug] Patch mixin for schema update and add support for pre-built rules as custom rules (#6603) @eric-forte-elastic
- [Bug] KQL non-quoted spaces parsing support (#6388) @eric-forte-elastic
- [Bug] Edge case rule loading bugs (#6532) @eric-forte-elastic
- [Bug] Use built-in
github.tokenfor Branch Version Status Checks (#6531) @eric-forte-elastic - [Bug] Pin ruff version to fix failing CI (#6494) @eric-forte-elastic
- [Bug] Allow ES|QL Dynamic Fields in Alert Suppression Schema Test (#6476) @eric-forte-elastic
- [Bug] Fix MITRE v19 testing harness (#6470) @eric-forte-elastic
🛠 Internal Changes
- [Bug] Patch mixin for schema update and add support for pre-built rules as custom rules (#6603) @eric-forte-elastic
- [Bug] KQL non-quoted spaces parsing support (#6388) @eric-forte-elastic
- [FR] Add nested KQL query support in lib/kql (#6492) @imays11
- [Bug] Edge case rule loading bugs (#6532) @eric-forte-elastic
- [FR] Add XDR rule tag taxonomy to Copilot PR review (#6591) @Mikaayenson
- Update 9.5.0 Beats and ECS schemas (#6590) @shashank-elastic
- Monthly Manifest and Schema Refresh + investigation guides (#6565) @shashank-elastic
- [Rule Tuning] Add Resources: LLM tag for ES|QL COMPLETION rules (#6506) @Mikaayenson
- chore: bump setup tools (#6545) @eric-forte-elastic
- Add API schemas for 9.5 (#6550) @shashank-elastic
- Add Data Source tags to the ML detection rules (#6511) @sodhikirti07
- [Bug] Pin ruff version to fix failing CI (#6494) @eric-forte-elastic
- [Bug] Allow ES|QL Dynamic Fields in Alert Suppression Schema Test (#6476) @eric-forte-elastic
- Prep for Release 9.5 (#6474) @shashank-elastic
- [Bug] Fix MITRE v19 testing harness (#6470) @eric-forte-elastic
dev-v2.0.0
Note
This major version adds support for MITRE v19 mappings. These are automatically used on stack versions >= 9.5 with tags dynamically added appropriately. If you want to use the v19 mappings on stack versions <=9.4 you will need to specify DR_THREAT_MAPPING_FRAMEWORK="MITRE ATT&CK" and DR_THREAT_MAPPING_VERSION=1 or add threat_mapping_framework: "MITRE ATT&CK" and threat_mapping_version: "19" to your _config.yaml. For more details, see docs-dev/multi-version-threat-mappings.md.
Note
This is also a breaking change if you are on main and have not upgraded to a 9.5 stack. The emitted related integrations now use >= instead of ^ which is expected to not function on older stacks. Please make sure your stack schema map and/or packages.yml are set according to your stack.
Changes
- [Rule Tuning] Misc. Linux LPE Rules (#6465) @Aegrah
- [Rule Tuning] Lucene Network Rules Language Conversion (#6463) @eric-forte-elastic
- [Rule Tuning] Web Application Suspicious Activity: POST Request Declined (#6469) @eric-forte-elastic
- [New Rule/Tuning] PHP File Creation in WordPress Plugin Directory (#6473) @Aegrah
- [Rule Tuning] Accepted Default Telnet Port Connection (#6461) @eric-forte-elastic
- [Rule Tuning] Entra ID / M365 Consent Grant Suppression (#6452) @terrancedejesus
- [New Rule] Azure AKS API Server Proxying Request to Kubelet (#6428) @terrancedejesus
- [New Rule] Entra ID ROPC Authentication with Unknown Client ID (#6454) @terrancedejesus
- [New Rule] Unusual Azure VM Extension Installed; Suspicious Child Process via Azure VM CustomScript Extension (#6277) @terrancedejesus
- [Rule Tuning] AWS Discovery API Calls from VPN ASN for the First Time by Identity (#6450) @bryans3c
- [New Rule] AWS Cognito Unauthenticated Identity Pool Credentials Issued (#6443) @bryans3c
- [New Rule] AWS CloudTrail Management Events Disabled via PutEventSelectors (#6442) @bryans3c
- [New Rule] AWS GuardDuty Detection Suppression (#6441) @bryans3c
- [New Rule] AWS Attempt to Leave Organization (#6440) @bryans3c
- [New Rule] AWS Account Closed (#6438) @bryans3c
- [New Rule] AWS IAM User Console Login Without MFA (#6437) @bryans3c
- [New Rule] AWS Potential Cryptomining via ECS Task Definition Deployment (#6399) @bryans3c
- [New Rule] AWS Bedrock AgentCore Execution Role Used Outside Its Runtime (#6398) @bryans3c
- [Rule Tuning] File Creation in World-Writable Directory by Unusual Process (#6416) @Mikaayenson
- [Rule Tuning] Kernel Module Load via Built-in Utility (#6459) @Mikaayenson
- [New Rules] GCP GKE Rules Conversion Part 2 (#6430) @imays11
- [New Rule] Microsoft Defender XDR Promotion Rules (#6360) @terrancedejesus
- Update Packetbeat ML detection rules to align with the migration to the network module (#6389) @sodhikirti07
- [Rule Tuning] Severity Promotions for AWS rules (#6403) @terrancedejesus
- [Rule Tuning] Severity Promotions for Azure / Entra / M365 Rules (#6401) @terrancedejesus
- [Tuning] Ransomware over SMB rules (#6402) @Samirbous
- [New Rule] AWS Bedrock Model Prompt or Completion Containing Credentials (#6400) @bryans3c
- [Rule Tuning] Severity Promotions for GCP/GWS rules (#6404) @terrancedejesus
- [Rule Tuning] Excessive AWS S3 Object Encryption with SSE-C (#6433) @bryans3c
- [Rule Tuning] Unusual AWS S3 Object Encryption with SSE-C (#6432) @bryans3c
- [New Rules] AWS Bedrock AgentCore Runtime Prompt Credential Access (x2) + integration manifest (#6406) @bryans3c
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#6434) @bryans3c
- [Rule Tuning] AWS Lambda Function URL Created with Public Access (#6412) @bryans3c
- [New Rules] GCP GKE Rule Conversions - part 1 (#6397) @imays11
- [New Rule] AWS Bedrock API Key Phantom User Activity Outside Bedrock (#6385) @bryans3c
- [New Rule] AWS Bedrock API Key Used for Destructive or Anti-Recovery Action (#6386) @bryans3c
- [New Rule] AWS IAM Credentials Added to a Bedrock API Key Phantom User (#6384) @bryans3c
- [New Rule] Entra ID Potential Conditional Access MFA Bypass via First-Party Microsoft Graph Access (#6325) @terrancedejesus
- [New Rule] Entra ID Device Registration with Phishing Kit Default OS Build (#6354) @terrancedejesus
- [New Rule] Entra ID AiTM Phishing-Kit Chain Detected (#6359) @terrancedejesus
- [Rule Tuning] Microsoft Graph Request Email Access by Unusual User and Client (#6378) @terrancedejesus
- [New Rule] Entra ID / M365 - Unusual ROPC Auth and/or Legacy Clients (#6377) @terrancedejesus
- [New Rule] Entra ID Multiple Device Registrations by a Single User (#6350) @terrancedejesus
- [New Rule] Microsoft Entra ID Impossible Travel Sign-in (#6150) @terrancedejesus
- [Rule Tuning] Entra ID OAuth Device Code Phishing via AiTM (#6358) @terrancedejesus
- [New Rules] Linux ER Rule Migrations - Part 1 (#6371) @Aegrah
- [New] GKE Kubernetes Rules (#6357) @Samirbous
- [New Rule] GenAI CLI Started with Unsafe Permission Bypass (#6232) @Mikaayenson
- [Rule Tuning] Misc GenAI Rule Tuning (#6231) @Mikaayenson
- [Rule Tuning] Windows Misc Tunings (#6379) @w0rk3r
- [Rule Tuning] First Time Seen DNS Query to RMM Domain (#6380) @w0rk3r
- [New Rule] Azure Virtual Machine Configuration Modified (#6278) @terrancedejesus
- [Tuning] Kubernetes Secret get or list from Node or Pod Service Account (#6229) @Samirbous
- [New/Tuning] DNS Tunneling via NsLookup (#6381) @Samirbous
- [New Rule] Potential ICMP Tunneling Activity to the Internet (#6352) @eric-forte-elastic
- [New Rule] ICMP Timestamp or Information Request from the Internet (#6349) @eric-forte-elastic
- [New Rule] ICMP Redirect Message from Internal Host (#6351) @eric-forte-elastic
- [New Rule] Deprecated TLS Version or Weak Cipher Negotiated Externally (#6353) @eric-forte-elastic
- [New Rule] Potential DHCP Starvation via High Client MAC Cardinality (#6355) @eric-forte-elastic
- [New Rules] Linux ER Rule Migrations - Part 2 (#6372) @Aegrah
- [New] Protected Storage Service Access via SMB (#6333) @Samirbous
- [New Rule] Potential Container Escape via Kernel core_pattern Modification (#6374) @Aegrah
- [New Rules] Duplicating Less Strict Linux LPE Rules from ER to DR (#6376) @Aegrah
- [New] Potential SQL Injection Against Microsoft SQL Server (#6364) @Samirbous
- [New] Web Server Cloud Metadata SSRF Request (#6375) @Samirbous
- [Rule Tuning/Deprecation] Linux DR Maintenance (#6373) @Aegrah
- [New Rule] Systemd Service Override Configuration File Created (#6254) @Aegrah
- [Rule Tuning] Align Microsoft Graph Email Access /me Path Predicate (#6335) @raylee-hawkins
- [Rule Tuning] First Time Seen Remote Monitoring and Management Tool (#6326) @w0rk3r
- [Rule Tuning] Credential Acquisition via Registry Hive Dumping (#6362) @w0rk3r
- [Tuning] Web Server Potential SQL Injection Request (#6365) @Samirbous
- [New Rule] AWS ECR Repository or Registry Policy Granted Public Access (#6342) @bryans3c
- [New Rule] AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content (#6347) @bryans3c
- [New Rule] AWS IAM User Console Login from Multiple Geolocations (#6348) @bryans3c
- [Rule Tuning] RDP (Remote Desktop Protocol) from the Internet (#6369) @eric-forte-elastic
- [Rule Tuning] Persistence via Suspicious Launch Agent or Launch Daemon (#6332) @Mikaayenson
- [New Rule] Splunk Enterprise PostgreSQL Sidecar Pre-Auth RCE (CVE-2026-20253) (#6279) @eric-forte-elastic
- [Rule Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#6252) @Mikaayenson
- [New Rule] SMB (Windows File Sharing) Activity from the Internet (#6267) @eric-forte-elastic
- [New Rule] Potential SSH Reverse Port Forwarding (#6330) @w0rk3r
- [Rule Tuning] Multiple Remote Management Tool Vendors on Same Host (#6331) @w0rk3r
- [Rule Tuning] remove URL/IP filtering from interactive curl/wget rule (#6356) @sammonsempes
- [New Rule] AWS Backup Vault Deleted or Vault Lock Removed (#6311) @bryans3c
- [New Rule] AWS Lambda Function High-Frequency Invocation by a Single Principal (#6298) @bryans3c
- [New Rule] AWS IAM Login Profile Created or Modified for an IAM User (#6303) @bryans3c
- [Rule Tuning] Refine scope of SMTP and IPSEC NAT Rules (#6307) @eric-forte-elastic
- [New Rule] AWS IAM Account Password Policy Deleted (#6302) @bryans3c
- [New Rule] AWS IAM Inline Policy Added to a Group (#6301) @bryans3c
- [New Rule] AWS IAM Permissions Boundary Modified or Removed (#6300) @bryans3c
- [New Rule] AWS Backup Recovery Point Deleted (#6310) @bryans3c
- [New Rule] AWS Lambda Function Invoked Cross-Account (#6299) @bryans3c
- [New Rule] Azure AD Graph Access with Unusual User and ASN (#6305) @terrancedejesus
- [New Rule] AWS KMS Imported Key Material Deleted (#6304) @bryans3c
- [New Rule] AWS Lambda Function Invoked from an Unusual Source ASN (#6297) @bryans3c
- [New Rule] AWS Lambda Function Invoked by an Unusual Principal (#6296) @bryans3c
- [New] Add detection rule for AMSI bypass via RPC NdrClientCall hook (4104) (#6321) @django-88
- [New Rule] AWS Lambda Function Policy Updated to Allow Cross-Account Invocation (#6295) @bryans3c
- [New Rule] AWS Lambda Function URL Created with Public Access (#6294) @bryans3c
- [New Rule] AWS Lambda Layer Shared Externally (#6293) @bryans3c
- [New Rule] AWS Lambda Function Deletion (#6291) @bryans3c
- [New Rule] AWS Lambda Event Source Mapping Creation (#6290) @bryans3c
- [New Rule] Google Workspace Impossible Travel Login (#6148) @terrancedejesus
- [New Rule] Azure AD Graph Access with Unusual Client and User (#6182) @terrancedejesus
- [New] MS Teams Rogue Help Desk (#6322) @Samirbous
- [New Rule] Azure AD Graph 4xx Error Surge from User (#6174) @terrancedejesus
- [New] Quick Assist Full Control Sharing Mode Enabled (#6319) @Samirbous
- [New] Java Dropped and Executed With DNS Lookup (#6320) @Samirbous
- [Rule Tunings] Google Workspace Domain-Wide Delegation and First Time OAuth Login (#6281) @imays11
- [Rule: Tuning] Increase coverage for the Remote SSH Log...
dev-v1.6.0
Note
Anyone who previously used import-rules-into-repo with Kibana API exports will have exception/action connector TOML files with Kibana internal ids in metadata.rule_ids instead of rule_id UUIDs. Those items won't match in scoped exports until re-imported.
Changes
- [Rule Tuning] Entra ID OAuth Device Code Grant by Unusual User (#5791) @terrancedejesus
- [New Rule] Entra ID Domain Federation Abuse (#5809) @terrancedejesus
- [New Rule] M365 SharePoint Site Sharing Policy Weakened (#5795) @terrancedejesus
- [Tuning] First Time Seen DNS Query to RMM Domain (#5819) @Samirbous
- [Rule Tuning] AWS Access Token Used from Multiple Addresses (#5785) @imays11
- [Tuning/New] RMM Rules (#5810) @Samirbous
- [New] Suspicious Execution from VS Code Extension (#5786) @Samirbous
- [New/Tuning] TeamPCP Simulation - New & Tuned Rules (#5812) @Aegrah
- [New] Elastic Defend Alert from GenAI Utility or Descendant (#5793) @Samirbous
- [New] Potential Account Takeover - Logon from New Source IP (#5770) @Samirbous
- [Rule Tuning] Base64 Decoded Payload Piped to Interpreter (#5811) @Aegrah
- [Rule Tuning]
kubernetes.audit.userAgent-->user_agent.originalConversion (#5808) @Aegrah - [Rule Tuning] RPC (Remote Procedure Call) from the Internet (#5805) @eric-forte-elastic
- [Rule Tuning] AWS STS Role Assumption by User (#5796) @imays11
- [Rule Tuning] Unusual Process For a Windows Host - from for … (#5797) @yuriShafet
- [Tuning] LSASS Process Access via Windows API (#5807) @Samirbous
- [Rule Tuning]
agent.id-->host.idnew_termsKey Modification (#5802) @Aegrah - [Tuning] Multiple Alerts on a Host Exhibiting CPU Spike (#5789) @Samirbous
- [Rule Tunings] Add Console Session Filtering to AWS Temporary Credential Detection Rules (#5781) @imays11
- [New Rule] Microsoft 365 SharePoint/OneDrive Sensitive Search and File Access (#5777) @terrancedejesus
- [New Rule] M365 MFA Notification Email Deleted or Moved (#5779) @terrancedejesus
- [New Rule] Okta User Authentication via Proxy Followed by Security Alert (#5752) @terrancedejesus
- [Rule Tuning] M365 OneDrive/SharePoint Excessive File Downloads (#5767) @terrancedejesus
- [Rule Tuning] Telnet Authentication Bypass Rule Tuning (#5771) @eric-forte-elastic
- [Rule Tuning] Panw Rules Tuning to Support Standard Logging (#5774) @eric-forte-elastic
- [New Rule] Microsoft UAL Security-Related Building-Block Signals (#5746) @terrancedejesus
- [Rule Tuning] Entra ID Federated Identity Credential Issuer Modified (#5763) @terrancedejesus
- [Rule Tuning] Entra ID Federated Identity Credential Issuer Modified (#5760) @terrancedejesus
- [Rule Tuning] Windows Misc Tuning - 2 (#5758) @w0rk3r
- [New Rules] Kernel Discovery & BPF Load/Tampering via bpftool (#5743) @Aegrah
- [New] FortiGate SSL VPN Login Followed by SIEM Alert by User (#5757) @Samirbous
- [New/Tuning] New LKM Load Rule & FN Tuning Tunneling Rules (#5742) @Aegrah
- [Rule Tuning] Kernel Module Load via Built-in Utility (#5736) @Aegrah
- [Tuning] Newly Seen FG or Suricata alert (#5734) @Samirbous
- [Rule Tuning] LLM Completion Rules (#5744) @Mikaayenson
- [Rule Deprecation] Deprecate Individual MSFT Compliance Rules (#5679) @terrancedejesus
- [Rule Tuning] Okta Credential Stuffing, Password Spraying, and Brute Force Detection Improvements (#5723) @terrancedejesus
- [Rule Tuning] Windows Misc Tunings (#5740) @w0rk3r
- [New] Correlated Alerts on Similar User Identities (#5726) @Samirbous
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5739) @imays11
- [New] Multiple Rare Elastic Defend Behavior Rules by Host (#5738) @Samirbous
- [Rule Tuning] Entra ID Federated Identity Credential Persistence Detection (#5702) @terrancedejesus
- [Rule Tuning] Accepted Default Telnet Port Connection (#5737) @eric-forte-elastic
- [Rule Tuning] Entra ID SharePoint Accessed by Unusual User and Microsoft Authentication Broker Client (#5681) @terrancedejesus
- [Tuning] High Order Rules fine tuning (#5728) @Samirbous
- [Rule Tuning] Entra ID Suspicious Cloud Device Registration (#5683) @terrancedejesus
- [New Rule] AWS SSM Inventory Reconnaissance by Rare User (#5724) @imays11
- [New Rule] AWS Sensitive IAM Operations Performed via CloudShell (#5718) @imays11
- [New Rules] AWS IAM new identity federation provider rules (#5691) @imays11
- [Tuning] Adds host metadata to the setup requirements (#5719) @Samirbous
- [New] Potential Notepad Markdown RCE Exploitation (#5729) @Samirbous
- [Rule Tuning] PowerShell Rules Revamp - 9 (#5706) @w0rk3r
- [Rule Deprecation] M365 Teams Guest & External Access Rules (#5721) @terrancedejesus
- [Rule Tuning] Potential Timestomp in Executable Files (#5727) @w0rk3r
- [Tuning] Elastic Agent Service Terminated (#5730) @Samirbous
- [New Rule] AWS GuardDuty Member Account Manipulation (#5688) @imays11
- [Rule Tuning] M365 Identity Excessive SSO Login Errors Reported (#5677) @terrancedejesus
- [Rule Tuning] System Information Discovery via dmidecode from Parent … (#5732) @Aegrah
- [New Rule] Okta Admin Console Login Failure (#5669) @terrancedejesus
- [tuning] LLM DNS queries (#5709) @Samirbous
- [New] Elastic Defend Alert Followed by Telemetry Loss (#5716) @Samirbous
- [Rule Tuning] Okta User Assigned Administrator Role (#5671) @terrancedejesus
- [New/Tuning] Misc. D4C Rules (#5710) @Aegrah
- [Rule Deprecation] PowerShell Rules (#5707) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 8 (#5705) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 7 (#5704) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 6 (#5700) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 5 (#5699) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 4 (#5698) @w0rk3r
- [New Rule] Potential PowerShell Obfuscated Script via High Entropy (#5554) @w0rk3r
- [New/Tuning] Misc. New D4C Rules and Tunings (#5692) @Aegrah
- [Tuning/New] Solarwinds Post Exploit (#5696) @Samirbous
- [New Rule] AWS EC2 Serial Console Access Enabled (#5687) @imays11
- [Rule Tuning] Update LLM Verdict for COMPLETION Rules (#5693) @Mikaayenson
- [New] Endpoint Rule Conversion PR (#5658) @DefSecSentinel
- [Rule Tuning] Adding D4C Compatibility to Compatible Container-Related Rules (#5685) @Aegrah
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5657) @imays11
- [Rule Tuning] Machine Learning Detected a Suspicious Windows Event (#5686) @yuriShafet
- MacOS detection rules tuning (#5667) @DefSecSentinel
- [New Rules] Misc. K8s RBAC Abuse Rules (#5673) @Aegrah
- [Tuning] M365 Exchange Inbox Phishing Evasion Rule Created (#5648) @Samirbous
- [Rule Tuning] Dormant & Deprecated Rule Clean-Up (#5672) @Aegrah
- [New Rules] ESQL LLM-Based Alert Triage Rules (#5656) @Mikaayenson
- [New Rule] Execution via OpenClaw Agent (#5666) @Mikaayenson
- [Rule Tuning] Unsigned DLL Side-Loading from a Suspicious Folder: Add Downloads path and fix subdirectory evasion (#5592) @ailiffa
- [New] SolarWinds Web Help Desk Java Module Load or Child Process (#5665) @Samirbous
- [Tuning] M365 Exchange Inbox Forwarding Rule Created (#5647) @Samirbous
- [Tuning] Component Object Model Hijacking (#5651) @Samirbous
- [Tuning] Svchost spawning Cmd (#5649) @Samirbous
- [New] Multiple Machine Learning Alerts by Influencer Field (#5660) @Samirbous
- [Rule Tuning] Full Kubernetes Ruleset (#5659) @Aegrah
- [New Rules] Misc. D4C Rules re: (un)Authenticated API Access (#5661) @Aegrah
- [Rule Tuning] Mythic C2 AzureBlob Profile Endpoints (#5663) @terrancedejesus
- [New Rule] Fortigate (FG-IR-26-060) Detections (#5641) @terrancedejesus
- [Rule Tuning] M365 Security Compliance Potential Ransomware Activity (#5653) @terrancedejesus
- [Tuning] Hosts File Modified (#5655) @Samirbous
- [New Rule] Okta AiTM Session Cookie Replay Detection (#5627) @terrancedejesus
- [New] Suspicious FortiGate and Fortinet Logon rules (#5640) @Samirbous
- [New] Newly Observed Process Exhibiting CPU Spike (#5635) @Samirbous
- chore: Fix lock version for 9.3.2 Release (#5634) @eric-forte-elastic
- [Rule Tuning] Accepted Default Telnet Port Connection (#5629) @eric-forte-elastic
- [Rule Tuning] PowerShell Rules Revamp - 2 (#5623) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 3 (#5625) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 1 (#5619) @w0rk3r
- [New] Multiple Alerts on a Host Exhibiting CPU Spike (#5621) @Samirbous
- [Rule Tuning] Entra ID OAuth Phishing via First-Party Microsoft Application (#5610) @terrancedejesus
- [New] Detection Alert on a Process Exhibiting CPU Spike (#5617) @Samirbous
- [New] Multiple Vulnerabilities by Asset via Wiz (#5598) @Samirbous
- [Tuning] ESQL Dynamic unique value fields (#5569) @Samirbous
- [New] Lateral Movement Alerts from a Newly Observed Entity (#5557) @Samirbous
- [Rule Tuning] Several Community DR Issues (#5615) @Aegrah
- [New/Tuning] General API Abuse D4C/K8s Rules (#5591) @Aegrah
- [New Rule] Curl SOCKS Proxy Detected via Defend for Containers (#5596) @Aegrah
- [New Rules] Reintroduction of Defend for Containers (D4C) Ruleset (#5561) @Aegrah
- [Tuning] Multiple Cloud Secrets Accessed by Source Address (#5618) @Samirbous
- Revert "[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578)" (#5620) @Mikaayenson
- [Tuning] Potential Ransomware Behavior - Note Files by System (#5595) @Samirbous
- [Tuning] Rare Connection to WebDAV Target (#5604) @Samirbous
- [Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578) @Aegrah
- [New] Potential Telnet Authentication Bypass (CVE-2026-24061) (#5612) @Samirbous
- [Rule Tuning] Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource (#5589) @terrancedejesus
- [Rule Tuning] Entra ID OAuth Device Code Flow with Concurrent Sign-ins (#5594) @terrancedejesus
- [Rule Tuning] M365 Threat Intelligence Signal (#5587) @terrancedejesus
- [New] Newly Observed Network Alert (#5585) @Samirbous
- [Tuning] Suricata and Elastic Defend Network Correlation (#558...
dev-v1.5.0
Changes
- [Tuning] AWS IAM Create User via Assumed Role on EC2 Instance (#5063) @imays11
- [Rule Tunings] AWS Route Table Created / AWS EC2 Route Table Modified or Deleted (#5064) @imays11
- [Rule Tuning] SSM Session Started to EC2 Instance (#5068) @imays11
- [Rule Tuning] Potential Okta MFA Bombing via Push Notifications (#5073) @terrancedejesus
- [Rule Tuning] AWS EC2 Instance Connect SSH Public Key Uploaded (#5069) @imays11
- [Rule Tunings] AWS DynamoDB new terms Rules (#5074) @imays11
- [Tuning] AWS S3 Unauthenticated Bucket Access by Rare Source (#5075) @imays11
- [Rule Tunings] AWS SNS New Terms Rules (#5082) @imays11
- [Tuning] AWS Access Token Used from Multiple Addresses (#5055) @imays11
- [Rule Tuning] Remote Execution via File Shares (#5066) @w0rk3r
- [Rule Tuning] PowerShell Rules (#5056) @w0rk3r
- [Rule Tuning] Component Object Model Hijacking (#5065) @w0rk3r
- [Rule Tuning] Windows High Severity - 1 (#5092) @w0rk3r
- [Rule Tuning] Windows High Severity - 2 (#5093) @w0rk3r
- [Rule Tuning] Windows High Severity - 3 (#5094) @w0rk3r
- [Rule Tuning] Fix process.pe.original_file_name Conditions (#5101) @w0rk3r
- [Rule Tuning] Windows High Severity - 4 (#5095) @w0rk3r
- [Rule Tuning] Windows High Severity - 5 (#5096) @w0rk3r
- [Rule Tuning] High-Severity Noisy Rules Conversion to new_terms (#5091) @w0rk3r
- [New] Microsoft Entra ID Protection Alert and Device Registration (#4688) @Samirbous
- [New Rule] Curl or Wget Spawned via Node.js (#5132) @Aegrah
- [Rule Tuning] Mark some field optional for 3rd party compatibility (#5135) @w0rk3r
- [Rule Tuning] Suspicious PowerShell Engine ImageLoad (#5134) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Elevated Access to User Access Administrator (#5107) @terrancedejesus
- [New Rule] Credential Access via TruffleHog Execution (#5129) @Aegrah
- [New Rule] GitHub Authentication Token Access via Node.js (#5130) @Aegrah
- [New Rule] Azure Storage Account Keys Accessed by Privileged User (#5141) @terrancedejesus
- [New Rule] Node.js Pre or Post-Install Script Execution (#5131) @Aegrah
- [Rule Tuning] Updated ESQL Rules Based on Validation Results (#5151) @eric-forte-elastic
- [Rule Tuning] Potential Port Scanning Activity from Compromised Host (#5161) @Aegrah
- [Rule Tuning] Azure AD Global Administrator Role Assigned (#5090) @terrancedejesus
- [Rule Tuning] Update Azure / M365 Mappings (#5153) @terrancedejesus
- [Rule Tuning] Update Azure / M365 Index Patterns and Lookback Windows (#5155) @terrancedejesus
- [New Rules] Potential CVE-2025-32463 Exploitation (#5169) @Aegrah
- [Tuning] Potential Ransomware Behavior - High count of Readme files by System (#5167) @Samirbous
- [New] Suspicious SeIncreaseBasePriorityPrivilege Use (#5150) @Samirbous
- [Tuning] Startup or Run Key Registry Modification (#5137) @Samirbous
- [Rule Tuning] Misc. Linux Community Tunings (#5160) @Aegrah
- [New Rule] Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt (#5166) @Aegrah
- [Rule Tuning] Unusual Instance Metadata Service (IMDS) API Request (#5163) @terrancedejesus
- [New Rule] Attempt to Clear Logs via Journalctl (#5170) @Aegrah
- [Rule Tuning] Azure Entra ID Rare App ID for Principal Authentication (#5184) @terrancedejesus
- [New Rule] Entra ID Actor Token User Impersonation Abuse (#5136) @terrancedejesus
- [New Rule] Azure Storage Account Blob Public Access Enabled (#5139) @terrancedejesus
- [New Rule] Azure RBAC Built-In Administrator Roles Assigned (#5113) @terrancedejesus
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5149) @imays11
- [Rule Tuning] AWS STS Role Chaining (#5180) @imays11
- [Rule Tuning] AWS S3 Bucket Enumeration or Brute Force (#5173) @imays11
- [Rule Tuning] Check if registry.data.strings is null on exclusion-based logic (#5193) @w0rk3r
- [Tuning] Simple HTTP Web Server Connection (#5209) @Samirbous
- [Rule Tuning] Excessive Secret or Key Retrieval from Azure Key Vault (#5220) @Mikaayenson
- [New] Potential Command Shell via NetCat (#5221) @Samirbous
- [Rule Tunings] AWS Root Access Rules (#5218) @imays11
- [Rule Tuning][Deprecation] AWS Root Console Login Rules (#5201) @imays11
🚀 Features
- Pin dependencies (#5086) @elastic-renovate-prod[bot]
- Update investigation guides (#5112) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5123) @github-actions[bot]
- Add SIEM package category (#5128) @shashank-elastic
- Monthly Schema Updates (#5187) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5188) @github-actions[bot]
- Update Package Category (#5192) @shashank-elastic
- feat: ESQL query validation against Elastic cluster (#4955) @traut
🐛 Bug Fixes
- [Bug] Github Gist API Now Requires Auth (#5119) @eric-forte-elastic
- Added handling for unauth error (#5115) @eric-forte-elastic
- [Bug] Annotated Fields Ignored (#5125) @eric-forte-elastic
- [Bug] Add Dataclass Require Fields to the CLI Prompt (#5159) @eric-forte-elastic
- [Bug] Add unit tests and fix Alert Suppression schema validation for ThresholdQueryRuleData (#5196) @eric-forte-elastic
🛠 Internal Changes
- Bootstrap repository (#5085) @elastic-backstage-prod[bot]
dev-v1.4.0
Changes
- Delete Development Rules (#5084) @shashank-elastic
- Fix updated_date for tunings as part of #5079 (#5081) @shashank-elastic
- Tune Rules that have unsupported versions in min_stack_version (#5079) @shashank-elastic
- [Rule Tuning] Beats & Endgame Indices (#5072) @Mikaayenson
- [Rule Tuning] D-Bus Service Created (#5076) @Aegrah
- [Rule Tuning] Adjust process.code_signature.trusted condition (#5067) @w0rk3r
- [Rule Tuning] Remote File Download via PowerShell (#5062) @w0rk3r
- [Rule Tuning] Untrusted Driver Loaded (#5061) @w0rk3r
- [Rule Tuning] Connection to Commonly Abused Web Services (#5060) @w0rk3r
- Tune a Tag discrepency in rule (#5053) @shashank-elastic
- [Tuning] System File Ownership Change (#5051) @Samirbous
- [Rule Tuning] Misc. Linux ES|QL Rules (#5050) @Aegrah
- [New Rules] Potential Relay Attack against a Computer Account (#4826) @w0rk3r
- [Tuning] Unusual Network Activity from a Windows System Binary (#5048) @Samirbous
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 10 (#5025) @w0rk3r
- [New] Active Directory Discovery using AdExplorer (#5047) @Samirbous
- [New] Connection to Common Large Language Model Endpoints (#5044) @Samirbous
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 16 (#5038) @w0rk3r
- [New] Potential System Tampering via File Modification (#5043) @Samirbous
- [New/Tuning] Windows Rules to detect top threats/TTPs 24/25 (#5001) @Samirbous
- [Rule Tuning] 3rd Party EDR Compatibility - Adjust CS Windows Paths (#5037) @w0rk3r
- [Rule Tuning] Suspicious DLL Loaded for Persistence or Privilege Escalation (#5039) @w0rk3r
- [Rule Tuning] M365 Portal Logins (Impossible & Atypical) (#5031) @terrancedejesus
- [New Rule] Toolshell Exploit Chain Detections (#4928) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID Suspicious Session Reuse to Graph Access (#4997) @terrancedejesus
- [New Rule] Threat Intelligence Signal - Microsoft Defender for Office 365 (#4994) @terrancedejesus
- [Rule Tuning] Multi-Factor Authentication Disabled for User (#5006) @terrancedejesus
- [Tuning] First Occurrence of STS GetFederationToken Request by User (#5007) @imays11
- [Tuning] First Time AWS Cloudformation Stack Creation by User (#5036) @imays11
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 13 (#5028) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 15 (#5030) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 14 (#5029) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 12 (#5027) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 11 (#5026) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 9 (#5024) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 8 (#5023) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 7 (#5022) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 6 (#5021) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 5 (#5020) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 4 (#5019) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 3 (#5018) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 2 (#5017) @w0rk3r
- [Rule Tuning] Windows - Small Adjusts for Compatibility (#5032) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 1 (#5016) @w0rk3r
- [Tuning] Unusual Network Connection to Suspicious Web Service (#5008) @Samirbous
- [Rule Tuning] First Time Seen AWS Secret Value Accessed in Secrets Manager (#4992) @imays11
- [Rule Tuning] AWS STS GetCallerIdentity API Called for the First Time (#4995) @imays11
- [New Rule] Multi-Base64 Decoding Attempt from Suspicious Location (#4931) @Aegrah
- [Rule Tuning] AWS STS AssumeRole with New MFA Device (#4999) @imays11
- [Tuning] Connection to Commonly Abused Web Services - alerts JetBrains to GH (#4973) @Samirbous
- [Rule Tuning] Suspicious Windows Powershell Arguments (#4961) @w0rk3r
- [Rule Tuning] ES|QL PowerShell Rules (#4984) @w0rk3r
- [Rule Tuning] Potential RemoteMonologue Attack (#4967) @w0rk3r
- [New] Command Line Obfuscation via Whitespace Padding (#4860) @Samirbous
- [Rule Tuning] Suspicious PrintSpooler Service Executable File Creation (#4976) @w0rk3r
- [tuning] Unusual Persistence via Services Registry (#4989) @Samirbous
- [Tuning] SDH - Investigating MFA Deactivation with no Re-Activation for Okta User Account (#4986) @imays11
- [New Rule] Potential Web Shell ASPX File Creation (#4939) @w0rk3r
- [Rule Tuning] PowerShell Script Block Logging Disabled (#4980) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Suspicious Session Reuse to Graph Access (#4954) @terrancedejesus
- [Rule Tuning] Creation or Modification of Root Certificate (#4970) @w0rk3r
- [Rule Tuning] Fixes FPs related to a process.args_count bug (#4971) @w0rk3r
- [Rule Tuning] ESQL Query Field Dynamic Field Standardization (#4912) @terrancedejesus
- [Rule Tuning] Elastic Security External Alerts (#4962) @Mikaayenson
- [Rule Tuning] AI4DSOC External Promotion Alerts (#4959) @Mikaayenson
- [New Rule] Unusual Web Config File Access (#4927) @w0rk3r
- [Rule Tuning] Script Execution via Microsoft HTML Application (#4950) @w0rk3r
- [Rule Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4946) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID MFA TOTP Brute Force Attempts (#4937) @terrancedejesus
- [Rule Tuning] Azure Key Vault Secret Key Usage by Unusual Identity (#4925) @shashank-elastic
- [Rule Tuning] OIDC Discovery URL Changed in Entra ID (#4923) @Mikaayenson
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4922) @github-actions[bot]
- [New Rule] Potential Impersonation Attempt via Kubectl (#4833) @Aegrah
- [Rule Tuning] AWS EC2 AMI Shared with Another Account (#4914) @imays11
- [Rule Deprecation] Deprecated - AWS EC2 Snapshot Activity (#4913) @imays11
- [Rule Tunings] Reduce Usage of Flattened Fields in AWS Rules (#4892) @imays11
- [New Rule] OIDC Discovery URL Changed in Entra ID (#4908) @terrancedejesus
- [New Rule] Azure Key Vault Secret Key Usage by Unusual Identity (#4900) @terrancedejesus
- [New Rule] External Authentication Method Addition or Modification in Entra ID (#4906) @terrancedejesus
- [New Rule] Excessive Secret or Key Retrieval from Azure Key Vault (#4898) @terrancedejesus
- [New Rule] Kubernetes Unusual Decision by User Agent (#4829) @Aegrah
- [Rule Tuning] Azure Key Vault Modified (#4896) @terrancedejesus
- [New Rule] Unusual Kill Signal (#4911) @Aegrah
- [Rule Tuning] Sudoers File Modification (#4904) @Aegrah
- [Rule Tuning] AWS IAM API Calls via Temporary Session Tokens (#4901) @imays11
- [Rule Deprecation] Azure Virtual Network Device Modified or Deleted (#4889) @terrancedejesus
- [New Rule] TeamFiltration User-Agents Detected (#4868) @terrancedejesus
- Add investigation guides for detection rules (#4886) @shashank-elastic
- [New Rule] Suspicious Entra ID OAuth User Impersonation Scope Detected (#4876) @terrancedejesus
- [Rule Tuning] PowerShell Windows Defender ATP DataCollection Scripts (#4867) @w0rk3r
- [Rule Tuning] Windows Misc Tuning (#4870) @w0rk3r
- [New Rule] Unusual ROPC Login Attempt by User Principal (#4871) @terrancedejesus
- [New Rule] Kubectl Apply Pod from URL (#4855) @Aegrah
- [New Rule] Kubernetes Events Deleted (#4853) @Aegrah
- [Rule Tuning] Potential Linux Tunneling and/or Port Forwarding (#4858) @Aegrah
- [New Rule] Kubernetes Sensitive Configuration File Activity (#4849) @Aegrah
- [New Rule] Microsoft Entra ID Suspicious Cloud Device Registration (#4802) @terrancedejesus
🚀 Features
- [FR] Refactor Schema Validation & Support Multi-Dataset Sequence Validation (#5059) @Mikaayenson
- Fix Ruff failures (#5083) @shashank-elastic
- Add test_min_stack_version_supported testcase (#5077) @shashank-elastic
- [FR] Add negate DOES NOT MATCH capability to IM rule type (>=9.2) (#5041) @Mikaayenson
- [FR] Add support for 5 group_by fields in threshold rules (>=9.2) (#5040) @Mikaayenson
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5049) @github-actions[bot]
- Monthly Schema Updates (#5046) @shashank-elastic
- Add all rule types DaC testing (#4969) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4991) @github-actions[bot]
- Investigation guides Update (#4990) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4963) @github-actions[bot]
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4960) @github-actions[bot]
- [FR] [DAC] Add Arbitrary File location Support for Local Creation Date (#4915) @eric-forte-elastic
- [FR] Add white space checking for KQL parse (#3789) @eric-forte-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4926) @github-actions[bot]
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4924) @github-actions[bot]
- Investigation guides Update (#4920) @shashank-elastic
- Clarify authentication settings to Kibana related to #4495 (#4819) @m-a-leclercq
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4887) @github-actions[bot]
- Prep 8.19/9.1 (#4869) @shashank-elastic
🐛 Bug Fixes
- [Bug] Incorrect Integrations Schema Parsing for Nested Fields (#5058) @eric-forte-elastic
- [Bug] Rule Toml Write Formatting Wrongly Formats \\x (#4978) @eric-forte-elastic
- [Bug] [DAC] Custom Rules Filter Discrepancy on Stacks Upgraded to 8.18 (#4945) @eric-forte-elastic
- fix: Allow different order of the metadata fields in ESQL queries (#4956) @traut
- [FR] [DAC] Add existing mitre threat information on import (#4948) @Mikaayenson
- [Bug] [DAC] Kibana Export Rules Rule Name ...
dev-v1.3.0
Rule Updates
- [New Rule] Potential Kubectl Masquerading (#4832) @Aegrah
- [New BBR] Kubectl Configuration Discovery (#4835) @Aegrah
- [New Rule] Kubectl Network Configuration Modification (#4836) @Aegrah
- [New Rule] Kubernetes Direct API Request via Curl or Wget (#4841) @Aegrah
- [New Rule] Kubernetes Forbidden Creation Request (#4843) @Aegrah
- [Rule Tunings] AWS SSM Command Document Created by Rare User (#4848) @imays11
- [Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#4854) @Samirbous
- [Deprecation] Suspicious File Creation in /etc for Persistence (#4850) @Aegrah
- [New Rule] Excessive Microsoft 365 Mailbox Items Accessed (#4825) @terrancedejesus
- [Rule Tuning] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4847) @terrancedejesus
- [New BBR] Kubectl Workload and Cluster Discovery (#4830) @Aegrah
- [New Rule] Entra ID RT to PRT Transition from Same User and Device (#4845) @terrancedejesus
- [Tuning] First Time Seen Commonly Abused Remote Access Tool Execution (#4842) @Samirbous
- [Rule Tunings] AWS Role Assumption By Service / User (#4827) @imays11
- [Rule Tuning] AWS SSM
SendCommandExecution by Rare User (#4828) @imays11 - [Rule Tuning] Suspicious Microsoft 365 Mail Access by Unusual ClientAppId (#4806) @terrancedejesus
- [Rule Tuning] First Time Seen NewCredentials Logon Process (#4844) @w0rk3r
- [Rule Tuning] Sharpening Kubernetes Rules Indices (#4822) @Aegrah
- [Rule Tuning] Added Kubernetes Domain Tag (#4831) @Aegrah
- [Tuning] Elevation via SCM rules (#4837) @Samirbous
- [New Rule] Forbidden Request from Unusual User Agent in Kubernetes (#4818) @Aegrah
- [New Rule] Suspicious ADRS Token Request by Microsoft Auth Broker (#4801) @terrancedejesus
- [New Rule] Entra ID User Signed In from Unusual Device (#4804) @terrancedejesus
- [Rule Tuning] Expand Scope of Entra ID Brute Force Sign-In Attempts (#4777) @terrancedejesus
- [Tuning] High Number of Process and/or Service Terminations" (#4813) @Samirbous
- [New Rule] Kubernetes Service Account Secret Access (#4816) @Aegrah
- [Rule Tuning] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4793) @terrancedejesus
- [New Rules] SPN Spoofing / Coercion Rules (#4815) @w0rk3r
- [Rule Tuning] AWS IAM Assume Role Policy Update (#4799) @imays11
- [Rule Tuning] AWS EC2 User Data Retrieval for EC2 Instance (#4808) @imays11
- [New Rule] AWS CloudTrail Log Evasion (#4788) @imays11
- [Rule Tuning] AWS EC2 Deprecated AMI Discovery (#4784) @imays11
- [Rule Tuning] PowerShell ES|QL Rules Tuning (#4785) @w0rk3r
- [New Rule] Kubeconfig File Creation or Modification (#4810) @Aegrah
- [New Rule] Kubeconfig File Discovery (#4811) @Aegrah
- [Rule Tuning] Container Management Utility Run Inside A Container (#4809) @Aegrah
- [New Rule] Kubectl Permission Discovery (#4812) @Aegrah
- [FN Rule Tuning] Kubernetes User Exec into Pod (#4814) @Aegrah
- [New] Potential Machine Account Relay Attack via SMB (#4803) @Samirbous
- [Rule Tuning] Outlook Home Page Registry Modification (#4798) @w0rk3r
- [Tuning] Downloaded URL Files (#4794) @Samirbous
- [New] Potential CVE-2025-33053 Exploitation (#4795) @Samirbous
- [Rule Deprecation] Azure Entra Sign-in Brute Force Microsoft 365 Accounts by Repeat Source (#4780) @terrancedejesus
- [New Rule] Microsoft Entra ID Excessive Account Lockouts Detected (#4782) @terrancedejesus
- [Tuning] Unusual Parent-Child Relationship (#4775) @Samirbous
- [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role (#4774) @imays11
- [Rule Tunings] AWS EC2 Flow Log Deletion and Network ACL Activity (#4778) @imays11
- [Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765) @Aegrah
- [Rule Tuning][New Rule][Deprecation] AWS EC2 EBS Snapshot Activity Rules (#4763) @imays11
- [New Rule] BloodHound Suite User-Agents Detected (#4769) @terrancedejesus
- [New Rule] Entra ID Protection - Risk Detection - User Risk (#4762) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID Protection Anonymized IP Risk Detection (#4759) @terrancedejesus
- [Rule Tuning] Shell Configuration Creation or Modification (#4766) @Aegrah
- [Tuning] AWS Access Token Used from Multiple Addresses (#4753) @imays11
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4756) @github-actions[bot]
- [New Rule] Microsoft 365 Suspicious Inbox Rule to Delete or Move Emails (#4743) @terrancedejesus
- [New] Disabling Lsa Protection via Registry Modification (#4747) @Samirbous
- [Rule Tuning] Tuning Azure Entra Sign-in Brute Force against Microsoft 365 Accounts (#4737) @terrancedejesus
- [New Rule] Microsoft Entra ID Elevated Access to User Access Administrator (#4742) @terrancedejesus
- [New Rule] Microsoft Entra ID User Reported Suspicious Activity (#4740) @terrancedejesus
- [Rule Tuning] Tuning Microsoft Entra ID High Risk Sign-in (#4739) @terrancedejesus
- [New] BadSuccessor dMSA Abuse Detections (#4745) @Samirbous
- [Rule Tuning] Tuning Microsoft 365 Global Administrator Role Assigned (#4738) @terrancedejesus
- [Tuning] Lateral Movement Rules (#4736) @Samirbous
- [Tuning] Account Discovery Command via SYSTEM Account (#4734) @Samirbous
- [Rule Tuning] Microsoft Graph First Occurrence of Client Request (#4728) @terrancedejesus
- [New Rule] Multiple Microsoft 365 User Account Lockouts in Short Time Window (#4717) @terrancedejesus
- [Rule Tuning] Potential Microsoft 365 User Account Brute Force (#4716) @terrancedejesus
- [New Rule] Microsoft Entra ID Protection - Risk Detections (#4725) @terrancedejesus
- [Rule Tuning] Startup or Run Key Registry Modification (#4710) @w0rk3r
- [Rule Tuning] Unusual Scheduled Task Update (#4714) @w0rk3r
- [Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4723) @Samirbous
- [Rule Tuning] Backup Deletion with Wbadmin (#4715) @w0rk3r
- [New Rule] Suspicious Email Access by First-Party Application via Microsoft Graph (#4704) @terrancedejesus
- [New Rule] Microsoft Entra Session Reuse with Suspicious Graph Access (#4711) @terrancedejesus
- [Rule Tuning] Unusual File Creation - Alternate Data Stream (#4712) @w0rk3r
- [Rule Tuning] Tuning
Suspicious Mailbox Permission Delegation in Exchange Online(#4705) @terrancedejesus - Fix new term doc broken link (#4706) @shashank-elastic
- [Rule Tuning] Add exceptions for non-interactive signin failures for Entra M365 Bruteforce (#4405) @jvalente-salemstate
- [New Rule] Unusual Exim4 Child Process (#4684) @Aegrah
- [New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683) @Aegrah
- [New Rule] Linux Telegram API Request (#4677) @Aegrah
- [Rule Tuning] Reduce Severity from Critical to High (#4637) @w0rk3r
- [New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685) @Aegrah
- [New Rule] Potential Dynamic IEX Reconstruction via Environment Variables (#4633) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Service Principal Addition Invoked by MSFT Identity (#4700) @terrancedejesus
- [New Rule] Potential PowerShell Obfuscation via Special Character Overuse (#4632) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion (#4631) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion (#4630) @w0rk3r
- [New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion (#4629) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation (#4615) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences (#4614) @w0rk3r
- [New Rule] PowerShell Obfuscation via Negative Index String Reversal (#4610) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Reverse Keywords (#4609) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction (#4608) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via String Concatenation (#4607) @w0rk3r
- [New Rule] System Binary Symlink to Suspicious Location (#4682) @Aegrah
- [New Rule] Suspicious Named Pipe Creation (#4681) @Aegrah
- [New Rule] Suspicious Kernel Feature Activity (#4676) @Aegrah
- [New Rule] Potential Data Exfiltration Through Curl (#4678) @Aegrah
- [New/Tuning] Potential Hex Payload Execution via Command-Line (#4675) @Aegrah
- [New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674) @Aegrah
- [New] Windows Sandbox with Sensitive Configuration (#4606) @Samirbous
- [New] Rare Connection to WebDAV Target (#4667) @Samirbous
- [New] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4673) @Samirbous
- [New Rule] Git Repository or File Download to Suspicious Directory (#4663) @Aegrah
- [New Rule] Manual Mount Discovery via /etc/exports (#4662) @Aegrah
- [New Rule] Docker Release File Creation (#4661) @Aegrah
- [New Rule] Manual Memory Dumping via Proc Filesystem (#4660) @Aegrah
- [FN Tuning] Suspicious /proc/maps Discovery (#4659) @Aegrah
- [New Rule] Suspicious Path Mounted (#4664) @Aegrah
- [Tuning] Connection to Commonly Abused Web Services (#4686) @Samirbous
- [New] Concurrent Azure SignIns with Suspicious Properties (#4670) @Samirbous
- [New] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4691) @Samirbous
- [New Rule] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4687) @terrancedejesus
- [New Rule] Microsoft Entra ID SharePoint Access for User Principal via Auth Broker (#4695) @terrancedejesus
- [New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658) @Aegrah
🚀 Features
- docs-builder: add
pull-requests: writepermission to docs-build workflow (#4840) @reakaleek - Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4820) @github-actions[bot]
- [FR] Update Docs for Prebuilt Rule Customization (#4787) @eric-forte-elastic
- [FR] Add Ability to Filter Rule Exports from Kibana (#4783) @Eric-Fort...
dev-v1.2.0
Changes
- [New] Microsoft 365 OAuth Redirect to Device Registration for User (#4694) @Samirbous
- [New Rule] Adding Coverage for
Microsoft Entra ID Protection Anonymized IP Risk Detection(#4689) @terrancedejesus - [New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client (#4642) @terrancedejesus
- [New Rule] Adding Coverage for
AWS S3 Static Site JavaScript File Uploaded(#4617) @terrancedejesus - [New Rule] Adding Coverage for
AWS IAM or STS API Calls via Temporary Session Tokens(#4628) @terrancedejesus
🚀 Features
- Deprecate Experimental ML command (#4669) @shashank-elastic
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4679) @github-actions[bot]
- Bringing back "fix: Cleaning up the hashable content for the rule" (#4621) (#4668) @traut
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4665) @shashank-elastic
- [Tuning] Update DPRK ByBit Hunting Queries (#4645) @DefSecSentinel
🐛 Bug Fixes
- fix: Fixing leftover references to
sha256method (#4690) @traut - fix: missed version bump (#4655) @traut
- fix: temporarily reverting "Cleaning up the hashable content for the rule (#4621)" (#4654) @traut
🛠 Internal Changes
- Deprecate Experimental ML command (#4669) @shashank-elastic
- fix: Fixing leftover references to
sha256method (#4690) @traut - Bringing back "fix: Cleaning up the hashable content for the rule" (#4621) (#4668) @traut
🔍 Hunting Updates
- [Tuning] Update DPRK ByBit Hunting Queries (#4645) @DefSecSentinel
dev-v1.1.0
Changes
- [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648) @imays11
- Fix versions for changes in required_fileds (#4640) @shashank-elastic
- [Rule Tuning] User Added to Privileged Group in Active Directory (#4646) @w0rk3r
- [Rule Tuning] Replace legacy winlog.api usage (#4647) @w0rk3r
- [New] Suspicious Azure Sign-in via Visual Studio Code (#4639) @Samirbous
- [New] RemoteMonologue Attack rules (#4604) @Samirbous
- [New Rule] Potential Malicious PowerShell Based on Alert Correlation (#4635) @w0rk3r
- [Deprecate] LaunchDaemon Creation or Modification and Immediate Loading (#4547) @DefSecSentinel
- [New Rule] Potential PowerShell Obfuscation via String Reordering (#4595) @w0rk3r
- [Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4627) @w0rk3r
- [New Rule] Dynamic IEX Reconstruction via Method String Access (#4634) @w0rk3r
- [Tuning] MacOS DR Tuning PR (#4546) @DefSecSentinel
- [New Rule] Adding Coverage for
AWS CLI with Kali Linux Fingerprint Identified(#4625) @terrancedejesus - [New Rule] Adding Coverage for
AWS IAM Virtual MFA Device Registration(#4626) @terrancedejesus - [New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses (#4624) @terrancedejesus
- [Rule Tuning] Adjusting
Microsoft Entra ID Rare Authentication Requirement for Principal User(#4562) @terrancedejesus - [Rule Tuning] Suspicious WMI Event Subscription Created (#4618) @w0rk3r
- [Rule Tuning] SSH Authorized Keys File Deletion (#4591) @w0rk3r
- [D4C Conversion] Converting Compatible D4C Rules to DR (#4532) @Aegrah
- [FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529) @Aegrah
- [Rule Tuning] Suspicious Execution via Scheduled Task (#4599) @w0rk3r
- [Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules (#4592) @w0rk3r
- [New] Unusual Network Connection to Suspicious Top Level Domain (#4563) @DefSecSentinel
- [New] Unusual Network Connection to Suspicious Web Service (#4569) @DefSecSentinel
- [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4589) @w0rk3r
- [Tuning] Microsoft Windows Defender Tampering (#4573) @Samirbous
- [Rule Tuning] Tuning Illicit Grant Consent Detections in Azure and M365 (#4557) @terrancedejesus
- [Rule Tuning] Tuning
Azure Conditional Access Policy Modified(#4558) @terrancedejesus - [Deprecation] Deprecating
Azure Virtual Network Device Modified or Deleted(#4559) @terrancedejesus - Update Max signals value to supported limits (#4556) @shashank-elastic
- [Rule Tuning] Added OWA (outlook for web) new AppID (#4568) @BugOrFeature
- [Rule Tuning] Adjusting Investigation Guide for
First Occurrence of Entra ID Auth via DeviceCode Protocol(#4490) @terrancedejesus
🚀 Features
- fix: Cleaning up the hashable content for the rule (#4621) @traut
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4649) @github-actions[bot]
- [Enhancement] Add flag to export rules via KQL search on name (#4594) @frederikb96
- [FR] Add Support for Local Dates Flag (#4582) @eric-forte-elastic
- [FR] Add Kibana Action Connector Error to Exception List Workaround (#4583) @eric-forte-elastic
- [FR] Update Detection Rules MITRE Workflow to SHA Pin (#4581) @eric-forte-elastic
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4601) @github-actions[bot]
- Add investigation guides (#4600) @shashank-elastic
- [maintenance] Update docset.yml (#4590) @Mikaayenson
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4571) @github-actions[bot]
- Prep main for 9.1 (#4555) @shashank-elastic
- [Bug] Update Custom Rules Markdown Location (#4565) @eric-forte-elastic
- Create new detection rule set documentation to be included in the new docs. (#4508) @Mpdreamz
🐛 Bug Fixes
- [Bug] Update Schema Prompt to include new_terms_fields (#4567) @eric-forte-elastic
🛠 Internal Changes
- fix: Cleaning up the hashable content for the rule (#4621) @traut
- Add 8.18 and 9.0 beats schemas (#4641) @shashank-elastic
- [New Rule] Threat Intel Email Indicator Match (#4598) @w0rk3r
- [Bug] Update Schema Prompt to include new_terms_fields (#4567) @eric-forte-elastic
- [Enhancement] Add flag to export rules via KQL search on name (#4594) @frederikb96
- Feature exclude tactic name (#4593) @frederikb96
- [FR] Add Support for Local Dates Flag (#4582) @eric-forte-elastic
- [FR] Add Kibana Action Connector Error to Exception List Workaround (#4583) @eric-forte-elastic
- Remove Task List reference (#4605) @shashank-elastic
- [maintenance] Update docset.yml (#4590) @Mikaayenson
- Prep main for 9.1 (#4555) @shashank-elastic
- [Bug] Update Custom Rules Markdown Location (#4565) @eric-forte-elastic
- Create new detection rule set documentation to be included in the new docs. (#4508) @Mpdreamz
🔍 Hunting Updates
- [New Hunt] New Hunting Queries for DPRK ByBit (#4644) @terrancedejesus
- [Rule Tuning] Tuning
Azure Service Principal Credentials Added(#4570) @terrancedejesus
dev-v1.0.0
Changes
- [New Rule] Adding Coverage for DynamoDB Exfiltration Behaviors (#4535) @terrancedejesus
- Change description and name of problemchild ML detection-rules (#4545) @sodhikirti07
- [Tuning] Suspicious .NET Reflection via PowerShell (#4543) @Samirbous
- Deprecate Cloud Defend Rules (#4537) @shashank-elastic
- [Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4533) @Samirbous
- [New Rule] File Creation in /var/log via Suspicious Process (#4528) @Aegrah
- [New Rule] Adding Coverage for
Azure Entra Password Spraying (Non-Interactive SFA)(#4523) @terrancedejesus - [New Rule] Adding Coverage for
Azure Entra Rare App ID for Principal Authentication(#4524) @terrancedejesus - [New Rule] Adding Coverage for
Azure Entra Rare Instance of Single-Factor Authentication for User(#4525) @terrancedejesus - Deprecation Notice to Cloud Defend Rules (#4520) @shashank-elastic
- [New Rule] Uncommon Destination Port Connection by Web Server (#4515) @Aegrah
- [New Rule] Unusual File Creation from Web Server Parent (#4514) @Aegrah
- [New/Tuning] Docker Socket Enumeration (#4510) @Aegrah
- [New Rules] Potential Port/Subnet Scanning Activity from Compromised Host (#4509) @Aegrah
- [New Rule] Unusual Process Spawned from Web Server Parent (#4513) @Aegrah
- [New Rule] Unusual Command Execution from Web Server Parent (#4512) @Aegrah
- Added ML detection-rules for new Security Host package (#4519) @sodhikirti07
- [New Rules] Azure OpenAI (#3701) @Mikaayenson
- [New] WDAC Policy File by an Unusual Process (#4504) @Samirbous
- Deprecate an APM BBR rule (#4511) @shashank-elastic
- [New Rule] Python Site or User Customize File Creation (#4500) @Aegrah
- [New Rule] Python Path File (pth) Creation (#4499) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual User (#4481) @Aegrah
- [Rule Tuning] Remove hardcoded logic from description (#4503) @w0rk3r
- [New Rule] Kill Command Execution (#4485) @Aegrah
- [New Rule] Unusual File Transfer Utility Launched (#4487) @Aegrah
- [New Rule] Base64 Decoded Payload Piped to Interpreter (#4488) @Aegrah
- [New Rule] Unusual Base64 Encoding/Decoding Activity (#4486) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual IP-Address (#4482) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual SSH Public Key (#4478) @Aegrah
- [New Rule] Linux User Account Credential Modification (#4484) @Aegrah
- [New Rule] SSH Authorized Keys File Deletion (#4483) @Aegrah
- [Tuning] Remote File Copy to a Hidden Share (#4494) @Samirbous
- [Tuning] Potential Antimalware Scan Interface Bypass via PowerShell (#4477) @Samirbous
- [Rule Tuning] Sysmon rules that uses
event.action(#4496) @w0rk3r - [New Rule] Remote File Creation in World Writeable Directory (#4475) @Aegrah
- [New Rule] Potential Malware-Driven SSH Brute Force Attempt (#4474) @Aegrah
- [New Rule] High Number of Egress Network Connections from Unusual Executable (#4473) @Aegrah
- [New Rule] Unusual Remote File Creation (#4476) @Aegrah
- [Rule Tuning] MsBuild Making Network Connections (#4479) @w0rk3r
- [Rule Tuning] Adapt Rules to work with Sysmon (#4480) @w0rk3r
- [Tuning] Potential Evasion via Filter Manager (#4493) @Samirbous
- [New Rule] Adding Coverage for
M365 OneDrive Excessive File Downloads with OAuth Token(#4469) @terrancedejesus - [Rule Tuning] Expanding coverage for
First Occurrence of Entra ID Auth via DeviceCode Protocol(#4466) @terrancedejesus - [New Rule] Adding Coverage for
AWS SNS Topic Created by Rare User(#4455) @terrancedejesus - Fix spacing in Setup information (#4470) @shashank-elastic
- [Rule Tuning] Tighten Up Windows EventLog Indexes, Improve tags (#4464) @w0rk3r
- [Rule Tuning] Account Configured with Never-Expiring Password (#4459) @w0rk3r
- [Rule Tuning] Windows - Improve Index Pattern Consistency (#4462) @w0rk3r
- [Rule Tuning] Event Aggregation - Fix
event.action&event.typeconditions (#4445) @w0rk3r - [Tuning] Execution of a Downloaded Windows Script (#4452) @Samirbous
- [Rule Tuning] Decrease Interval to 1m for Endpoint Promotions (#4450) @Mikaayenson
- [Rule Tuning] SMB Connections via LOLBin or Untrusted Process (#4444) @w0rk3r
- [Rule Tuning] Tighten Up Elastic Defend Indexes - Linux (#4446) @w0rk3r
- [Rule Tuning] Tighten Up Elastic Defend Indexes - MacOS (#4447) @w0rk3r
- [Rule Tuning] Remote Execution via File Shares (#4448) @w0rk3r
- [Rule Tuning] Port Scan Rules (#4443) @Aegrah
- Fix remaining Replace master doc URLs with current (#4441) @shashank-elastic
- [Tuning / New] Execution of a downloaded windows script (#4434) @Samirbous
- [New Rule] Process Backgrounded by Unusual Parent (#4431) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 6 (#4423) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 5 (#4422) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 4 (#4421) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 3 (#4420) @Aegrah
- [Rule Tuning] December-January AWS Rule Tuning (#4425) @terrancedejesus
- [Rule Tuning] Potential OpenSSH Backdoor Logging Activity (#4429) @Aegrah
- [New Rule] Suspicious Usage of bpf_probe_write_user Helper (#4426) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 2 (#4417) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 1 (#4416) @Aegrah
- [Tuning] Unusual Instance Metadata Service (IMDS) API Request (#4418) @Samirbous
- [Rule Tuning] Improve Detection Compatibility with Non-English Logs (#4410) @w0rk3r
- Fix S1 minstack version (#4415) @shashank-elastic
- [FR] Add Remaining Guides (#4412) @Mikaayenson
- [New Rule] File with Right-to-Left Override Character Created/Executed (#4396) @w0rk3r
- [New Rule] Unusual D-Bus Daemon Child Process (#4397) @Aegrah
- [New Rule] Adding Coverage for
AWS S3 Unauthenticated Bucket Access by Rare Source(#4315) @terrancedejesus - [Rule Tuning] Add Public Snapshot Coverage Regarding
AWS EC2 EBS Snapshot Shared or Made Public(#4335) @terrancedejesus - [New Rule] Polkit Version Discovery (#4378) @Aegrah
- [New Rule] Polkit Policy Creation (#4379) @Aegrah
- [New Rule] Unusual Pkexec Execution (#4380) @Aegrah
- [New Rule] NetworkManager Dispatcher Script Creation (#4381) @Aegrah
- [New Rule] D-Bus Service Created (#4382) @Aegrah
- [New Rule] Manual Dracut Execution (#4383) @Aegrah
- [New Rule] Dracut Module Creation (#4384) @Aegrah
- [New Rule] OpenSSL Password Hash Generation (#4385) @Aegrah
- [New Rule] Boot File Copy (#4386) @Aegrah
- [New Rule] Initramfs Unpacking via unmkinitramfs (#4387) @Aegrah
- [New Rule] Initramfs Extraction via CPIO (#4389) @Aegrah
- [Tuning] Powershell Rules (#4395) @Samirbous
- [Rule Tuning] Linux Persistence Rules (#4393) @Aegrah
- [New Rule] Systemd Shell Execution During Boot (#4392) @Aegrah
🚀 Features
- [FR] Bump changed-files Version to Patched Version (#4542) @eric-forte-elastic
- [ci] Add new docs-builder automation. (#4507) @Mpdreamz
- Prep for Release 9.0 (#4550) @shashank-elastic
- [New Rules] Add new ML detection rules for Privileged Access Detection with Min Stack (#4549) @eric-forte-elastic
- Add new ML detection rules for Privileged Access Detection (#4516) @sodhikirti07
- Temporaily Disable Changed FIles Workflow (#4538) @eric-forte-elastic
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4531) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4530) @github-actions[bot]
- [FR] [DaC] Update Readme with DaC Support References (#4526) @eric-forte-elastic
- [FR] Add Env Var DR_CLI_MAX_WIDTH and DaC Docs Updates (#4518) @eric-forte-elastic
- chore: use
docs-devinstead ofdocsdir for docs (#4522) @traut - Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4463) @github-actions[bot]
- Modify Unit Test to Support Alert Suppression for EQL Sequences (#4457) @shashank-elastic
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4453) @github-actions[bot]
- Bumping number of versions per rule to 4 in total (#4451) @traut
- chore(ci): new CI action trigger for REACT testing workflow (#4435) @traut
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4442) @github-actions[bot]
- Add prerelease version for sentinel_one_cloud_funnel (#4438) @shashank-elastic
- Refresh ECS & Beats schemas, Integration manifests & schemas (#4436) @shashank-elastic
- [FR] Generate investigation guides (#4358) @Mikaayenson
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4400) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md (#4398) @github-actions[bot]
🐛 Bug Fixes
- fix: removing outdated code in Kibana client auth (#4495) @traut
- fix(ci): use negative patterns in
pathsinstead ofpaths-ignore(#4521) @traut - [Bug] [DaC] Fix Typo in CLI.md (#4491) @eric-forte-elastic
🛠 Internal Changes
- fix: removing outdated code in Kibana client auth (#4495) @traut
- [ci] Add new docs-builder automation. (#4507) @Mpdreamz
- Prep for Release 9.0 (#4550) @shashank-elastic
- [New Rules] Add new ML detection rules for Privileged Access Detection with Min Stack (#4549) @eric-forte-elastic
- [Revert] "Add new ML detection rules for Privileged Access Detection (#4516)" (#4548) @eric-forte-elastic
- Add new ML detection rules for Privileged Access Detection (#4516) @sodhikirti07
- [FR] [DaC] Update Readme with DaC Support References (#4526) @eric-forte-elastic
- [FR] Add Env Var DR_CLI_MAX_WIDTH and DaC Docs Updates (#4518) @eric-forte-elastic
- chore: use
docs-devinstead ofdocsdir for docs (#4522) @traut - chore: adjust paths to track in REACT test CI workflow (#4498) @traut
- chore: Removing RTAs (#4437) @traut
- [Bug] [DaC] Fix T...
dev-v0.4.0
Changes
- [Tuning] SDH - Possible Consent Grant Attack via Azure-Registered Application by @imays11 in #4283
- [New Rule] Adding Coverage for Self-Created Login Profile for Root Accounts in AWS by @terrancedejesus in #4277
- [Rule Tuning] Update Okta and Github Min-Stack Versions for Release by @terrancedejesus in #4290
- [Rule Tuning] Remove Trailing Comma in
AWS IAM User Created Access Keys For Another Userby @terrancedejesus in #4292 - [Rule Tuning] Minstack endpoint rules with process.group.id fields by @shashank-elastic in #4294
- [New Rule] Adding Coverage for
Azure Entra MFA TOTP Brute Force Attemptsby @terrancedejesus in #4297 - [Rule Tuning] Lookback Times for Okta Multiple Session and AWS KMS Retrieval Rules by @terrancedejesus in #4324
- [New Rule] Endpoint Security Promotion Rules for Specific Events by @terrancedejesus in #3533
- [Tuning] Uncommon Registry Persistence Change by @rad9800 in #4286
- [Rule Tuning] Windows misc Rule Tuning by @w0rk3r in #4298
- [New Rule] PAM Version Discovery by @Aegrah in #4300
- [New Rule] Pluggable Authentication Module Creation in Unusual Directory by @Aegrah in #4302
- [New Rule] Unusual SSHD Child Process by @Aegrah in #4303
- [Rule Tuning] Creation or Modification of Pluggable Authentication Mo… by @Aegrah in #4304
- [New Rule] Unusual Preload Environment Variable Process Execution by @Aegrah in #4305
- [New Rule] Loadable Kernel Module Configuration File Creation by @Aegrah in #4307
- [New Rule] Simple HTTP Web Server Creation by @Aegrah in #4308
- [New Rule] Simple HTTP Web Server Connection by @Aegrah in #4309
- [Rule Tuning] Potential Persistence via File Modification by @Aegrah in #4310
- [New Rule] Kernel Object File Creation by @Aegrah in #4325
- [New Rule] Dynamic Linker (ld.so) Creation by @Aegrah in #4306
- [Tuning] Suspicious WMI Event Subscription Created by @Samirbous in #4327
- [New Rule] Pluggable Authentication Module Source Download by @Aegrah in #4301
- [New Rule] SSH via Backdoored System User by @Aegrah in #4336
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 1 by @w0rk3r in #4330
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 2 by @w0rk3r in #4333
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 9 by @w0rk3r in #4356
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 5 by @w0rk3r in #4346
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 6 by @w0rk3r in #4348
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 3 by @w0rk3r in #4343
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 4 by @w0rk3r in #4345
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 7 by @w0rk3r in #4349
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 8 by @w0rk3r in #4355
- [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 10 by @w0rk3r in #4357
- [Tuning] Potential SYN-Based Network Scan Detected by @Samirbous in #4366
- [Rule: Tuning] - Azure blob permission modification tagging - Correct tags by @jvalente-salemstate in #4371
- [Rule Tuning] Windows Misc BBR Tuning by @w0rk3r in #4368
- [New Rule] Potential Process Name Stomping with Prctl by @Aegrah in #4352
- [New] Sensitive Audit Policy Sub-Category Disabled by @Samirbous in #4373
- [Rule Tuning] Posh BBRs by @w0rk3r in #4372
- [Rule Tuning] Suspicious Communication App Child Process by @w0rk3r in #4369
- [New Rule] Adding Coverage for
AWS SQS Queue Purgeby @terrancedejesus in #4354 - [Rule Tuning] Adjusting Verbiage for
AWS EC2 Instance Connect SSH Public Key Uploadedby @terrancedejesus in #4334 - [New Rule] Adding Coverage for
AWS EC2 Deprecated AMI Discoveryby @terrancedejesus in #4328 - [New Rule] Adding Coverage for
SNS Topic Message Publish by Rare Userby @terrancedejesus in #4350 - [New Rule] Adding Coverage for
Unusual AWS S3 Object Encryption with SSE-Cby @terrancedejesus in #4377 - [New BBR] Linux System Information Discovery via Getconf by @Aegrah in #4337
- [New Rule] Suspicious Path Invocation from Command Line by @Aegrah in #4338
- [New Rule] System Binary Path File Permission Modification by @Aegrah in #4339
- [New Rules] Kernel Seeking/Unpacking Activity by @Aegrah in #4341
- [Deprecation] Deprecating
Potential Password Spraying of Microsoft 365 User Accountsby @terrancedejesus in #4394 - [New Rule] Process Started with Executable Stack by @Aegrah in #4340
- [New Rule] GRUB Configuration File Creation by @Aegrah in #4390
- [New Rule] GRUB Configuration Generation through Built-in Utilities by @Aegrah in #4391
🐛 Bug Fixes
- [Bug] [DaC] Metadata maturity field default mismatch and poor enforcement of rule naming conventions by @eric-forte-elastic in #4285
- [Bug] [DaC] Actions Connector Defaults to None by @eric-forte-elastic in #4376
🛠 Internal Changes
- Prep for Release 8.18 by @shashank-elastic in #4288
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 by @github-actions in #4291
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 by @github-actions in #4295
- Update versioning support for 8.17 by @shashank-elastic in #4296
- Enhance Readability of validation check failures by @shashank-elastic in #4299
- Provide Deprecate Warnings for Experimental ML commands by @shashank-elastic in #4365
- Monthly Refresh ECS & Beats schemas, Integration manifests & schemas. by @shashank-elastic in #4332
- Enhance Readability of KQL validation check failures by @shashank-elastic in #4329
- [Python] Ignore Hunting Doc Changes for Version Code Checks by @terrancedejesus in #4331
- Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md by @github-actions in #4344
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 by @github-actions in #4347
- [Maintenance] Repository Config Update by @terrancedejesus in #4359
- [Maintenance] Updated Navigator Gist Token pt 2 by @terrancedejesus in #4361
- [Maintenance] Repository Config Update pt 3 by @terrancedejesus in #4363
- [Maintenance] repository config update pt 4 by @terrancedejesus in #4364
- [Maintenance] repository config update pt 5 by @terrancedejesus in #4367
- [Maintenance] Remove hunting TOML files from repo version checks by @terrancedejesus in #4374
🔍 Hunting Updates
- [New Hunt] Adding Hunting Query for
AWS IAM Unusual AWS Access Key Usage for Userby @terrancedejesus in #4280 - [New Hunts] Adding Several Hunting PRs into this ...