Skip to content

dev-v0.4.0

Choose a tag to compare

@shashank-elastic shashank-elastic released this 04 Feb 14:44
· 1492 commits to main since this release
2ea674c

Changes

  • [Tuning] SDH - Possible Consent Grant Attack via Azure-Registered Application by @imays11 in #4283
  • [New Rule] Adding Coverage for Self-Created Login Profile for Root Accounts in AWS by @terrancedejesus in #4277
  • [Rule Tuning] Update Okta and Github Min-Stack Versions for Release by @terrancedejesus in #4290
  • [Rule Tuning] Remove Trailing Comma in AWS IAM User Created Access Keys For Another User by @terrancedejesus in #4292
  • [Rule Tuning] Minstack endpoint rules with process.group.id fields by @shashank-elastic in #4294
  • [New Rule] Adding Coverage for Azure Entra MFA TOTP Brute Force Attempts by @terrancedejesus in #4297
  • [Rule Tuning] Lookback Times for Okta Multiple Session and AWS KMS Retrieval Rules by @terrancedejesus in #4324
  • [New Rule] Endpoint Security Promotion Rules for Specific Events by @terrancedejesus in #3533
  • [Tuning] Uncommon Registry Persistence Change by @rad9800 in #4286
  • [Rule Tuning] Windows misc Rule Tuning by @w0rk3r in #4298
  • [New Rule] PAM Version Discovery by @Aegrah in #4300
  • [New Rule] Pluggable Authentication Module Creation in Unusual Directory by @Aegrah in #4302
  • [New Rule] Unusual SSHD Child Process by @Aegrah in #4303
  • [Rule Tuning] Creation or Modification of Pluggable Authentication Mo… by @Aegrah in #4304
  • [New Rule] Unusual Preload Environment Variable Process Execution by @Aegrah in #4305
  • [New Rule] Loadable Kernel Module Configuration File Creation by @Aegrah in #4307
  • [New Rule] Simple HTTP Web Server Creation by @Aegrah in #4308
  • [New Rule] Simple HTTP Web Server Connection by @Aegrah in #4309
  • [Rule Tuning] Potential Persistence via File Modification by @Aegrah in #4310
  • [New Rule] Kernel Object File Creation by @Aegrah in #4325
  • [New Rule] Dynamic Linker (ld.so) Creation by @Aegrah in #4306
  • [Tuning] Suspicious WMI Event Subscription Created by @Samirbous in #4327
  • [New Rule] Pluggable Authentication Module Source Download by @Aegrah in #4301
  • [New Rule] SSH via Backdoored System User by @Aegrah in #4336
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 1 by @w0rk3r in #4330
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 2 by @w0rk3r in #4333
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 9 by @w0rk3r in #4356
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 5 by @w0rk3r in #4346
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 6 by @w0rk3r in #4348
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 3 by @w0rk3r in #4343
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 4 by @w0rk3r in #4345
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 7 by @w0rk3r in #4349
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 8 by @w0rk3r in #4355
  • [Rule Tuning] Linux 3rd Party EDR Support - Crowdstrike and S1 - 10 by @w0rk3r in #4357
  • [Tuning] Potential SYN-Based Network Scan Detected by @Samirbous in #4366
  • [Rule: Tuning] - Azure blob permission modification tagging - Correct tags by @jvalente-salemstate in #4371
  • [Rule Tuning] Windows Misc BBR Tuning by @w0rk3r in #4368
  • [New Rule] Potential Process Name Stomping with Prctl by @Aegrah in #4352
  • [New] Sensitive Audit Policy Sub-Category Disabled by @Samirbous in #4373
  • [Rule Tuning] Posh BBRs by @w0rk3r in #4372
  • [Rule Tuning] Suspicious Communication App Child Process by @w0rk3r in #4369
  • [New Rule] Adding Coverage for AWS SQS Queue Purge by @terrancedejesus in #4354
  • [Rule Tuning] Adjusting Verbiage for AWS EC2 Instance Connect SSH Public Key Uploaded by @terrancedejesus in #4334
  • [New Rule] Adding Coverage for AWS EC2 Deprecated AMI Discovery by @terrancedejesus in #4328
  • [New Rule] Adding Coverage for SNS Topic Message Publish by Rare User by @terrancedejesus in #4350
  • [New Rule] Adding Coverage for Unusual AWS S3 Object Encryption with SSE-C by @terrancedejesus in #4377
  • [New BBR] Linux System Information Discovery via Getconf by @Aegrah in #4337
  • [New Rule] Suspicious Path Invocation from Command Line by @Aegrah in #4338
  • [New Rule] System Binary Path File Permission Modification by @Aegrah in #4339
  • [New Rules] Kernel Seeking/Unpacking Activity by @Aegrah in #4341
  • [Deprecation] Deprecating Potential Password Spraying of Microsoft 365 User Accounts by @terrancedejesus in #4394
  • [New Rule] Process Started with Executable Stack by @Aegrah in #4340
  • [New Rule] GRUB Configuration File Creation by @Aegrah in #4390
  • [New Rule] GRUB Configuration Generation through Built-in Utilities by @Aegrah in #4391

🐛 Bug Fixes

🛠 Internal Changes

🔍 Hunting Updates

  • [New Hunt] Adding Hunting Query for AWS IAM Unusual AWS Access Key Usage for User by @terrancedejesus in #4280
  • [New Hunts] Adding Several Hunting PRs into this Main PR by @Aegrah in #4342
  • [Hunt Tuning] Persistence via SSH Configurations and/or Keys by @Aegrah in #4351