Skip to content

Releases: elastic/detection-rules

dev-v2.1.0

Choose a tag to compare

@github-actions github-actions released this 10 Aug 14:21
199ad79

Changes

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

dev-v2.0.0

Choose a tag to compare

@eric-forte-elastic eric-forte-elastic released this 20 Jul 15:23
78ca714

Note

This major version adds support for MITRE v19 mappings. These are automatically used on stack versions >= 9.5 with tags dynamically added appropriately. If you want to use the v19 mappings on stack versions <=9.4 you will need to specify DR_THREAT_MAPPING_FRAMEWORK="MITRE ATT&CK" and DR_THREAT_MAPPING_VERSION=1 or add threat_mapping_framework: "MITRE ATT&CK" and threat_mapping_version: "19" to your _config.yaml. For more details, see docs-dev/multi-version-threat-mappings.md.

Note

This is also a breaking change if you are on main and have not upgraded to a 9.5 stack. The emitted related integrations now use >= instead of ^ which is expected to not function on older stacks. Please make sure your stack schema map and/or packages.yml are set according to your stack.

Changes

Read more

dev-v1.6.0

Choose a tag to compare

@github-actions github-actions released this 10 Mar 17:43
ce3916f

Note

Anyone who previously used import-rules-into-repo with Kibana API exports will have exception/action connector TOML files with Kibana internal ids in metadata.rule_ids instead of rule_id UUIDs. Those items won't match in scoped exports until re-imported.

Changes

Read more

dev-v1.5.0

Choose a tag to compare

@eric-forte-elastic eric-forte-elastic released this 10 Mar 17:24
c724631

Changes

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

  • Bootstrap repository (#5085) @elastic-backstage-prod[bot]

dev-v1.4.0

Choose a tag to compare

@github-actions github-actions released this 10 Sep 18:23
f0f7d21

Changes

🚀 Features

🐛 Bug Fixes

Read more

dev-v1.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Jul 13:41
1fb60d6

Rule Updates

  • [New Rule] Potential Kubectl Masquerading (#4832) @Aegrah
  • [New BBR] Kubectl Configuration Discovery (#4835) @Aegrah
  • [New Rule] Kubectl Network Configuration Modification (#4836) @Aegrah
  • [New Rule] Kubernetes Direct API Request via Curl or Wget (#4841) @Aegrah
  • [New Rule] Kubernetes Forbidden Creation Request (#4843) @Aegrah
  • [Rule Tunings] AWS SSM Command Document Created by Rare User (#4848) @imays11
  • [Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#4854) @Samirbous
  • [Deprecation] Suspicious File Creation in /etc for Persistence (#4850) @Aegrah
  • [New Rule] Excessive Microsoft 365 Mailbox Items Accessed (#4825) @terrancedejesus
  • [Rule Tuning] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4847) @terrancedejesus
  • [New BBR] Kubectl Workload and Cluster Discovery (#4830) @Aegrah
  • [New Rule] Entra ID RT to PRT Transition from Same User and Device (#4845) @terrancedejesus
  • [Tuning] First Time Seen Commonly Abused Remote Access Tool Execution (#4842) @Samirbous
  • [Rule Tunings] AWS Role Assumption By Service / User (#4827) @imays11
  • [Rule Tuning] AWS SSM SendCommand Execution by Rare User (#4828) @imays11
  • [Rule Tuning] Suspicious Microsoft 365 Mail Access by Unusual ClientAppId (#4806) @terrancedejesus
  • [Rule Tuning] First Time Seen NewCredentials Logon Process (#4844) @w0rk3r
  • [Rule Tuning] Sharpening Kubernetes Rules Indices (#4822) @Aegrah
  • [Rule Tuning] Added Kubernetes Domain Tag (#4831) @Aegrah
  • [Tuning] Elevation via SCM rules (#4837) @Samirbous
  • [New Rule] Forbidden Request from Unusual User Agent in Kubernetes (#4818) @Aegrah
  • [New Rule] Suspicious ADRS Token Request by Microsoft Auth Broker (#4801) @terrancedejesus
  • [New Rule] Entra ID User Signed In from Unusual Device (#4804) @terrancedejesus
  • [Rule Tuning] Expand Scope of Entra ID Brute Force Sign-In Attempts (#4777) @terrancedejesus
  • [Tuning] High Number of Process and/or Service Terminations" (#4813) @Samirbous
  • [New Rule] Kubernetes Service Account Secret Access (#4816) @Aegrah
  • [Rule Tuning] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4793) @terrancedejesus
  • [New Rules] SPN Spoofing / Coercion Rules (#4815) @w0rk3r
  • [Rule Tuning] AWS IAM Assume Role Policy Update (#4799) @imays11
  • [Rule Tuning] AWS EC2 User Data Retrieval for EC2 Instance (#4808) @imays11
  • [New Rule] AWS CloudTrail Log Evasion (#4788) @imays11
  • [Rule Tuning] AWS EC2 Deprecated AMI Discovery (#4784) @imays11
  • [Rule Tuning] PowerShell ES|QL Rules Tuning (#4785) @w0rk3r
  • [New Rule] Kubeconfig File Creation or Modification (#4810) @Aegrah
  • [New Rule] Kubeconfig File Discovery (#4811) @Aegrah
  • [Rule Tuning] Container Management Utility Run Inside A Container (#4809) @Aegrah
  • [New Rule] Kubectl Permission Discovery (#4812) @Aegrah
  • [FN Rule Tuning] Kubernetes User Exec into Pod (#4814) @Aegrah
  • [New] Potential Machine Account Relay Attack via SMB (#4803) @Samirbous
  • [Rule Tuning] Outlook Home Page Registry Modification (#4798) @w0rk3r
  • [Tuning] Downloaded URL Files (#4794) @Samirbous
  • [New] Potential CVE-2025-33053 Exploitation (#4795) @Samirbous
  • [Rule Deprecation] Azure Entra Sign-in Brute Force Microsoft 365 Accounts by Repeat Source (#4780) @terrancedejesus
  • [New Rule] Microsoft Entra ID Excessive Account Lockouts Detected (#4782) @terrancedejesus
  • [Tuning] Unusual Parent-Child Relationship (#4775) @Samirbous
  • [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role (#4774) @imays11
  • [Rule Tunings] AWS EC2 Flow Log Deletion and Network ACL Activity (#4778) @imays11
  • [Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765) @Aegrah
  • [Rule Tuning][New Rule][Deprecation] AWS EC2 EBS Snapshot Activity Rules (#4763) @imays11
  • [New Rule] BloodHound Suite User-Agents Detected (#4769) @terrancedejesus
  • [New Rule] Entra ID Protection - Risk Detection - User Risk (#4762) @terrancedejesus
  • [Rule Tuning] Microsoft Entra ID Protection Anonymized IP Risk Detection (#4759) @terrancedejesus
  • [Rule Tuning] Shell Configuration Creation or Modification (#4766) @Aegrah
  • [Tuning] AWS Access Token Used from Multiple Addresses (#4753) @imays11
  • Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4756) @github-actions[bot]
  • [New Rule] Microsoft 365 Suspicious Inbox Rule to Delete or Move Emails (#4743) @terrancedejesus
  • [New] Disabling Lsa Protection via Registry Modification (#4747) @Samirbous
  • [Rule Tuning] Tuning Azure Entra Sign-in Brute Force against Microsoft 365 Accounts (#4737) @terrancedejesus
  • [New Rule] Microsoft Entra ID Elevated Access to User Access Administrator (#4742) @terrancedejesus
  • [New Rule] Microsoft Entra ID User Reported Suspicious Activity (#4740) @terrancedejesus
  • [Rule Tuning] Tuning Microsoft Entra ID High Risk Sign-in (#4739) @terrancedejesus
  • [New] BadSuccessor dMSA Abuse Detections (#4745) @Samirbous
  • [Rule Tuning] Tuning Microsoft 365 Global Administrator Role Assigned (#4738) @terrancedejesus
  • [Tuning] Lateral Movement Rules (#4736) @Samirbous
  • [Tuning] Account Discovery Command via SYSTEM Account (#4734) @Samirbous
  • [Rule Tuning] Microsoft Graph First Occurrence of Client Request (#4728) @terrancedejesus
  • [New Rule] Multiple Microsoft 365 User Account Lockouts in Short Time Window (#4717) @terrancedejesus
  • [Rule Tuning] Potential Microsoft 365 User Account Brute Force (#4716) @terrancedejesus
  • [New Rule] Microsoft Entra ID Protection - Risk Detections (#4725) @terrancedejesus
  • [Rule Tuning] Startup or Run Key Registry Modification (#4710) @w0rk3r
  • [Rule Tuning] Unusual Scheduled Task Update (#4714) @w0rk3r
  • [Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4723) @Samirbous
  • [Rule Tuning] Backup Deletion with Wbadmin (#4715) @w0rk3r
  • [New Rule] Suspicious Email Access by First-Party Application via Microsoft Graph (#4704) @terrancedejesus
  • [New Rule] Microsoft Entra Session Reuse with Suspicious Graph Access (#4711) @terrancedejesus
  • [Rule Tuning] Unusual File Creation - Alternate Data Stream (#4712) @w0rk3r
  • [Rule Tuning] Tuning Suspicious Mailbox Permission Delegation in Exchange Online (#4705) @terrancedejesus
  • Fix new term doc broken link (#4706) @shashank-elastic
  • [Rule Tuning] Add exceptions for non-interactive signin failures for Entra M365 Bruteforce (#4405) @jvalente-salemstate
  • [New Rule] Unusual Exim4 Child Process (#4684) @Aegrah
  • [New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683) @Aegrah
  • [New Rule] Linux Telegram API Request (#4677) @Aegrah
  • [Rule Tuning] Reduce Severity from Critical to High (#4637) @w0rk3r
  • [New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685) @Aegrah
  • [New Rule] Potential Dynamic IEX Reconstruction via Environment Variables (#4633) @w0rk3r
  • [Rule Tuning] Microsoft Entra ID Service Principal Addition Invoked by MSFT Identity (#4700) @terrancedejesus
  • [New Rule] Potential PowerShell Obfuscation via Special Character Overuse (#4632) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion (#4631) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion (#4630) @w0rk3r
  • [New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion (#4629) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation (#4615) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences (#4614) @w0rk3r
  • [New Rule] PowerShell Obfuscation via Negative Index String Reversal (#4610) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Reverse Keywords (#4609) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction (#4608) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via String Concatenation (#4607) @w0rk3r
  • [New Rule] System Binary Symlink to Suspicious Location (#4682) @Aegrah
  • [New Rule] Suspicious Named Pipe Creation (#4681) @Aegrah
  • [New Rule] Suspicious Kernel Feature Activity (#4676) @Aegrah
  • [New Rule] Potential Data Exfiltration Through Curl (#4678) @Aegrah
  • [New/Tuning] Potential Hex Payload Execution via Command-Line (#4675) @Aegrah
  • [New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674) @Aegrah
  • [New] Windows Sandbox with Sensitive Configuration (#4606) @Samirbous
  • [New] Rare Connection to WebDAV Target (#4667) @Samirbous
  • [New] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4673) @Samirbous
  • [New Rule] Git Repository or File Download to Suspicious Directory (#4663) @Aegrah
  • [New Rule] Manual Mount Discovery via /etc/exports (#4662) @Aegrah
  • [New Rule] Docker Release File Creation (#4661) @Aegrah
  • [New Rule] Manual Memory Dumping via Proc Filesystem (#4660) @Aegrah
  • [FN Tuning] Suspicious /proc/maps Discovery (#4659) @Aegrah
  • [New Rule] Suspicious Path Mounted (#4664) @Aegrah
  • [Tuning] Connection to Commonly Abused Web Services (#4686) @Samirbous
  • [New] Concurrent Azure SignIns with Suspicious Properties (#4670) @Samirbous
  • [New] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4691) @Samirbous
  • [New Rule] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4687) @terrancedejesus
  • [New Rule] Microsoft Entra ID SharePoint Access for User Principal via Auth Broker (#4695) @terrancedejesus
  • [New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658) @Aegrah

🚀 Features

Read more

dev-v1.2.0

Choose a tag to compare

@github-actions github-actions released this 02 May 15:32
b3adc6d

Changes

  • [New] Microsoft 365 OAuth Redirect to Device Registration for User (#4694) @Samirbous
  • [New Rule] Adding Coverage for Microsoft Entra ID Protection Anonymized IP Risk Detection (#4689) @terrancedejesus
  • [New Rule] MSFT Tenant OAuth Phishing via First-Party VSCode Client (#4642) @terrancedejesus
  • [New Rule] Adding Coverage for AWS S3 Static Site JavaScript File Uploaded (#4617) @terrancedejesus
  • [New Rule] Adding Coverage for AWS IAM or STS API Calls via Temporary Session Tokens (#4628) @terrancedejesus

🚀 Features

🐛 Bug Fixes

  • fix: Fixing leftover references to sha256 method (#4690) @traut
  • fix: missed version bump (#4655) @traut
  • fix: temporarily reverting "Cleaning up the hashable content for the rule (#4621)" (#4654) @traut

🛠 Internal Changes

🔍 Hunting Updates

dev-v1.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Apr 09:04
80c4f7e

Changes

  • [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648) @imays11
  • Fix versions for changes in required_fileds (#4640) @shashank-elastic
  • [Rule Tuning] User Added to Privileged Group in Active Directory (#4646) @w0rk3r
  • [Rule Tuning] Replace legacy winlog.api usage (#4647) @w0rk3r
  • [New] Suspicious Azure Sign-in via Visual Studio Code (#4639) @Samirbous
  • [New] RemoteMonologue Attack rules (#4604) @Samirbous
  • [New Rule] Potential Malicious PowerShell Based on Alert Correlation (#4635) @w0rk3r
  • [Deprecate] LaunchDaemon Creation or Modification and Immediate Loading (#4547) @DefSecSentinel
  • [New Rule] Potential PowerShell Obfuscation via String Reordering (#4595) @w0rk3r
  • [Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4627) @w0rk3r
  • [New Rule] Dynamic IEX Reconstruction via Method String Access (#4634) @w0rk3r
  • [Tuning] MacOS DR Tuning PR (#4546) @DefSecSentinel
  • [New Rule] Adding Coverage for AWS CLI with Kali Linux Fingerprint Identified (#4625) @terrancedejesus
  • [New Rule] Adding Coverage for AWS IAM Virtual MFA Device Registration (#4626) @terrancedejesus
  • [New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses (#4624) @terrancedejesus
  • [Rule Tuning] Adjusting Microsoft Entra ID Rare Authentication Requirement for Principal User (#4562) @terrancedejesus
  • [Rule Tuning] Suspicious WMI Event Subscription Created (#4618) @w0rk3r
  • [Rule Tuning] SSH Authorized Keys File Deletion (#4591) @w0rk3r
  • [D4C Conversion] Converting Compatible D4C Rules to DR (#4532) @Aegrah
  • [FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529) @Aegrah
  • [Rule Tuning] Suspicious Execution via Scheduled Task (#4599) @w0rk3r
  • [Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules (#4592) @w0rk3r
  • [New] Unusual Network Connection to Suspicious Top Level Domain (#4563) @DefSecSentinel
  • [New] Unusual Network Connection to Suspicious Web Service (#4569) @DefSecSentinel
  • [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4589) @w0rk3r
  • [Tuning] Microsoft Windows Defender Tampering (#4573) @Samirbous
  • [Rule Tuning] Tuning Illicit Grant Consent Detections in Azure and M365 (#4557) @terrancedejesus
  • [Rule Tuning] Tuning Azure Conditional Access Policy Modified (#4558) @terrancedejesus
  • [Deprecation] Deprecating Azure Virtual Network Device Modified or Deleted (#4559) @terrancedejesus
  • Update Max signals value to supported limits (#4556) @shashank-elastic
  • [Rule Tuning] Added OWA (outlook for web) new AppID (#4568) @BugOrFeature
  • [Rule Tuning] Adjusting Investigation Guide for First Occurrence of Entra ID Auth via DeviceCode Protocol (#4490) @terrancedejesus

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

🔍 Hunting Updates

dev-v1.0.0

Choose a tag to compare

@github-actions github-actions released this 24 Mar 11:32
65170c3

Changes

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

Read more

dev-v0.4.0

Choose a tag to compare

@shashank-elastic shashank-elastic released this 04 Feb 14:44
2ea674c

Changes

  • [Tuning] SDH - Possible Consent Grant Attack via Azure-Registered Application by @imays11 in #4283
  • [New Rule] Adding Coverage for Self-Created Login Profile for Root Accounts in AWS by @terrancedejesus in #4277
  • [Rule Tuning] Update Okta and Github Min-Stack Versions for Release by @terrancedejesus in #4290
  • [Rule Tuning] Remove Trailing Comma in AWS IAM User Created Access Keys For Another User by @terrancedejesus in #4292
  • [Rule Tuning] Minstack endpoint rules with process.group.id fields by @shashank-elastic in #4294
  • [New Rule] Adding Coverage for Azure Entra MFA TOTP Brute Force Attempts by @terrancedejesus in #4297
  • [Rule Tuning] Lookback Times for Okta Multiple Session and AWS KMS Retrieval Rules by @terrancedejesus in #4324
  • [New Rule] Endpoint Security Promotion Rules for Specific Events by @terrancedejesus in #3533
  • [Tuning] Uncommon Registry Persistence Change by @rad9800 in #4286
  • [Rule Tuning] Windows misc Rule Tuning by @w0rk3r in #4298
  • [New Rule] PAM Version Discovery by @Aegrah in #4300
  • [New Rule] Pluggable Authentication Module Creation in Unusual Directory by @Aegrah in #4302
  • [New Rule] Unusual SSHD Child Process by @Aegrah in #4303
  • [Rule Tuning] Creation or Modification of Pluggable Authentication Mo… by @Aegrah in #4304
  • [New Rule] Unusual Preload Environment Variable Process Execution by @Aegrah in #4305
  • [New Rule] Loadable Kernel Module Configuration File Creation by @Aegrah in #4307
  • [New Rule] Simple HTTP Web Server Creation by @Aegrah in #4308
  • [New Rule] Simple HTTP Web Server Connection by @Aegrah in #4309
  • [Rule Tuning] Potential Persistence via File Modification by @Aegrah in #4310
  • [New Rule] Kernel Object File Creation by @Aegrah in #4325
  • [New Rule] Dynamic Linker (ld.so) Creation by @Aegrah in #4306
  • [Tuning] Suspicious WMI Event Subscription Created by @Samirbous in #4327
  • [New Rule] Pluggable Authentication Module Source Download by @Aegrah in #4301
  • [New Rule] SSH via Backdoored System User by @Aegrah in #4336
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 1 by @w0rk3r in #4330
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 2 by @w0rk3r in #4333
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 9 by @w0rk3r in #4356
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 5 by @w0rk3r in #4346
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 6 by @w0rk3r in #4348
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 3 by @w0rk3r in #4343
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 4 by @w0rk3r in #4345
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 7 by @w0rk3r in #4349
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 8 by @w0rk3r in #4355
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 10 by @w0rk3r in #4357
  • [Tuning] Potential SYN-Based Network Scan Detected by @Samirbous in #4366
  • [Rule: Tuning] - Azure blob permission modification tagging - Correct tags by @jvalente-salemstate in #4371
  • [Rule Tuning] Windows Misc BBR Tuning by @w0rk3r in #4368
  • [New Rule] Potential Process Name Stomping with Prctl by @Aegrah in #4352
  • [New] Sensitive Audit Policy Sub-Category Disabled by @Samirbous in #4373
  • [Rule Tuning] Posh BBRs by @w0rk3r in #4372
  • [Rule Tuning] Suspicious Communication App Child Process by @w0rk3r in #4369
  • [New Rule] Adding Coverage for AWS SQS Queue Purge by @terrancedejesus in #4354
  • [Rule Tuning] Adjusting Verbiage for AWS EC2 Instance Connect SSH Public Key Uploaded by @terrancedejesus in #4334
  • [New Rule] Adding Coverage for AWS EC2 Deprecated AMI Discovery by @terrancedejesus in #4328
  • [New Rule] Adding Coverage for SNS Topic Message Publish by Rare User by @terrancedejesus in #4350
  • [New Rule] Adding Coverage for Unusual AWS S3 Object Encryption with SSE-C by @terrancedejesus in #4377
  • [New BBR] Linux System Information Discovery via Getconf by @Aegrah in #4337
  • [New Rule] Suspicious Path Invocation from Command Line by @Aegrah in #4338
  • [New Rule] System Binary Path File Permission Modification by @Aegrah in #4339
  • [New Rules] Kernel Seeking/Unpacking Activity by @Aegrah in #4341
  • [Deprecation] Deprecating Potential Password Spraying of Microsoft 365 User Accounts by @terrancedejesus in #4394
  • [New Rule] Process Started with Executable Stack by @Aegrah in #4340
  • [New Rule] GRUB Configuration File Creation by @Aegrah in #4390
  • [New Rule] GRUB Configuration Generation through Built-in Utilities by @Aegrah in #4391

🐛 Bug Fixes

🛠 Internal Changes

🔍 Hunting Updates

  • [New Hunt] Adding Hunting Query for AWS IAM Unusual AWS Access Key Usage for User by @terrancedejesus in #4280
  • [New Hunts] Adding Several Hunting PRs into this ...
Read more