dev-v1.0.0
·
1350 commits
to refs/heads/main
since this release
Changes
- [New Rule] Adding Coverage for DynamoDB Exfiltration Behaviors (#4535) @terrancedejesus
- Change description and name of problemchild ML detection-rules (#4545) @sodhikirti07
- [Tuning] Suspicious .NET Reflection via PowerShell (#4543) @Samirbous
- Deprecate Cloud Defend Rules (#4537) @shashank-elastic
- [Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4533) @Samirbous
- [New Rule] File Creation in /var/log via Suspicious Process (#4528) @Aegrah
- [New Rule] Adding Coverage for
Azure Entra Password Spraying (Non-Interactive SFA)(#4523) @terrancedejesus - [New Rule] Adding Coverage for
Azure Entra Rare App ID for Principal Authentication(#4524) @terrancedejesus - [New Rule] Adding Coverage for
Azure Entra Rare Instance of Single-Factor Authentication for User(#4525) @terrancedejesus - Deprecation Notice to Cloud Defend Rules (#4520) @shashank-elastic
- [New Rule] Uncommon Destination Port Connection by Web Server (#4515) @Aegrah
- [New Rule] Unusual File Creation from Web Server Parent (#4514) @Aegrah
- [New/Tuning] Docker Socket Enumeration (#4510) @Aegrah
- [New Rules] Potential Port/Subnet Scanning Activity from Compromised Host (#4509) @Aegrah
- [New Rule] Unusual Process Spawned from Web Server Parent (#4513) @Aegrah
- [New Rule] Unusual Command Execution from Web Server Parent (#4512) @Aegrah
- Added ML detection-rules for new Security Host package (#4519) @sodhikirti07
- [New Rules] Azure OpenAI (#3701) @Mikaayenson
- [New] WDAC Policy File by an Unusual Process (#4504) @Samirbous
- Deprecate an APM BBR rule (#4511) @shashank-elastic
- [New Rule] Python Site or User Customize File Creation (#4500) @Aegrah
- [New Rule] Python Path File (pth) Creation (#4499) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual User (#4481) @Aegrah
- [Rule Tuning] Remove hardcoded logic from description (#4503) @w0rk3r
- [New Rule] Kill Command Execution (#4485) @Aegrah
- [New Rule] Unusual File Transfer Utility Launched (#4487) @Aegrah
- [New Rule] Base64 Decoded Payload Piped to Interpreter (#4488) @Aegrah
- [New Rule] Unusual Base64 Encoding/Decoding Activity (#4486) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual IP-Address (#4482) @Aegrah
- [New Rule] Successful SSH Authentication from Unusual SSH Public Key (#4478) @Aegrah
- [New Rule] Linux User Account Credential Modification (#4484) @Aegrah
- [New Rule] SSH Authorized Keys File Deletion (#4483) @Aegrah
- [Tuning] Remote File Copy to a Hidden Share (#4494) @Samirbous
- [Tuning] Potential Antimalware Scan Interface Bypass via PowerShell (#4477) @Samirbous
- [Rule Tuning] Sysmon rules that uses
event.action(#4496) @w0rk3r - [New Rule] Remote File Creation in World Writeable Directory (#4475) @Aegrah
- [New Rule] Potential Malware-Driven SSH Brute Force Attempt (#4474) @Aegrah
- [New Rule] High Number of Egress Network Connections from Unusual Executable (#4473) @Aegrah
- [New Rule] Unusual Remote File Creation (#4476) @Aegrah
- [Rule Tuning] MsBuild Making Network Connections (#4479) @w0rk3r
- [Rule Tuning] Adapt Rules to work with Sysmon (#4480) @w0rk3r
- [Tuning] Potential Evasion via Filter Manager (#4493) @Samirbous
- [New Rule] Adding Coverage for
M365 OneDrive Excessive File Downloads with OAuth Token(#4469) @terrancedejesus - [Rule Tuning] Expanding coverage for
First Occurrence of Entra ID Auth via DeviceCode Protocol(#4466) @terrancedejesus - [New Rule] Adding Coverage for
AWS SNS Topic Created by Rare User(#4455) @terrancedejesus - Fix spacing in Setup information (#4470) @shashank-elastic
- [Rule Tuning] Tighten Up Windows EventLog Indexes, Improve tags (#4464) @w0rk3r
- [Rule Tuning] Account Configured with Never-Expiring Password (#4459) @w0rk3r
- [Rule Tuning] Windows - Improve Index Pattern Consistency (#4462) @w0rk3r
- [Rule Tuning] Event Aggregation - Fix
event.action&event.typeconditions (#4445) @w0rk3r - [Tuning] Execution of a Downloaded Windows Script (#4452) @Samirbous
- [Rule Tuning] Decrease Interval to 1m for Endpoint Promotions (#4450) @Mikaayenson
- [Rule Tuning] SMB Connections via LOLBin or Untrusted Process (#4444) @w0rk3r
- [Rule Tuning] Tighten Up Elastic Defend Indexes - Linux (#4446) @w0rk3r
- [Rule Tuning] Tighten Up Elastic Defend Indexes - MacOS (#4447) @w0rk3r
- [Rule Tuning] Remote Execution via File Shares (#4448) @w0rk3r
- [Rule Tuning] Port Scan Rules (#4443) @Aegrah
- Fix remaining Replace master doc URLs with current (#4441) @shashank-elastic
- [Tuning / New] Execution of a downloaded windows script (#4434) @Samirbous
- [New Rule] Process Backgrounded by Unusual Parent (#4431) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 6 (#4423) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 5 (#4422) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 4 (#4421) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 3 (#4420) @Aegrah
- [Rule Tuning] December-January AWS Rule Tuning (#4425) @terrancedejesus
- [Rule Tuning] Potential OpenSSH Backdoor Logging Activity (#4429) @Aegrah
- [New Rule] Suspicious Usage of bpf_probe_write_user Helper (#4426) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 2 (#4417) @Aegrah
- [Rule Tuning] Linux DR Tuning - Part 1 (#4416) @Aegrah
- [Tuning] Unusual Instance Metadata Service (IMDS) API Request (#4418) @Samirbous
- [Rule Tuning] Improve Detection Compatibility with Non-English Logs (#4410) @w0rk3r
- Fix S1 minstack version (#4415) @shashank-elastic
- [FR] Add Remaining Guides (#4412) @Mikaayenson
- [New Rule] File with Right-to-Left Override Character Created/Executed (#4396) @w0rk3r
- [New Rule] Unusual D-Bus Daemon Child Process (#4397) @Aegrah
- [New Rule] Adding Coverage for
AWS S3 Unauthenticated Bucket Access by Rare Source(#4315) @terrancedejesus - [Rule Tuning] Add Public Snapshot Coverage Regarding
AWS EC2 EBS Snapshot Shared or Made Public(#4335) @terrancedejesus - [New Rule] Polkit Version Discovery (#4378) @Aegrah
- [New Rule] Polkit Policy Creation (#4379) @Aegrah
- [New Rule] Unusual Pkexec Execution (#4380) @Aegrah
- [New Rule] NetworkManager Dispatcher Script Creation (#4381) @Aegrah
- [New Rule] D-Bus Service Created (#4382) @Aegrah
- [New Rule] Manual Dracut Execution (#4383) @Aegrah
- [New Rule] Dracut Module Creation (#4384) @Aegrah
- [New Rule] OpenSSL Password Hash Generation (#4385) @Aegrah
- [New Rule] Boot File Copy (#4386) @Aegrah
- [New Rule] Initramfs Unpacking via unmkinitramfs (#4387) @Aegrah
- [New Rule] Initramfs Extraction via CPIO (#4389) @Aegrah
- [Tuning] Powershell Rules (#4395) @Samirbous
- [Rule Tuning] Linux Persistence Rules (#4393) @Aegrah
- [New Rule] Systemd Shell Execution During Boot (#4392) @Aegrah
🚀 Features
- [FR] Bump changed-files Version to Patched Version (#4542) @eric-forte-elastic
- [ci] Add new docs-builder automation. (#4507) @Mpdreamz
- Prep for Release 9.0 (#4550) @shashank-elastic
- [New Rules] Add new ML detection rules for Privileged Access Detection with Min Stack (#4549) @eric-forte-elastic
- Add new ML detection rules for Privileged Access Detection (#4516) @sodhikirti07
- Temporaily Disable Changed FIles Workflow (#4538) @eric-forte-elastic
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4531) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4530) @github-actions[bot]
- [FR] [DaC] Update Readme with DaC Support References (#4526) @eric-forte-elastic
- [FR] Add Env Var DR_CLI_MAX_WIDTH and DaC Docs Updates (#4518) @eric-forte-elastic
- chore: use
docs-devinstead ofdocsdir for docs (#4522) @traut - Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4463) @github-actions[bot]
- Modify Unit Test to Support Alert Suppression for EQL Sequences (#4457) @shashank-elastic
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4453) @github-actions[bot]
- Bumping number of versions per rule to 4 in total (#4451) @traut
- chore(ci): new CI action trigger for REACT testing workflow (#4435) @traut
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4442) @github-actions[bot]
- Add prerelease version for sentinel_one_cloud_funnel (#4438) @shashank-elastic
- Refresh ECS & Beats schemas, Integration manifests & schemas (#4436) @shashank-elastic
- [FR] Generate investigation guides (#4358) @Mikaayenson
- Lock versions for releases: 8.12,8.13,8.14,8.15,8.16,8.17 (#4400) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs/ATT&CK-coverage.md (#4398) @github-actions[bot]
🐛 Bug Fixes
- fix: removing outdated code in Kibana client auth (#4495) @traut
- fix(ci): use negative patterns in
pathsinstead ofpaths-ignore(#4521) @traut - [Bug] [DaC] Fix Typo in CLI.md (#4491) @eric-forte-elastic
🛠 Internal Changes
- fix: removing outdated code in Kibana client auth (#4495) @traut
- [ci] Add new docs-builder automation. (#4507) @Mpdreamz
- Prep for Release 9.0 (#4550) @shashank-elastic
- [New Rules] Add new ML detection rules for Privileged Access Detection with Min Stack (#4549) @eric-forte-elastic
- [Revert] "Add new ML detection rules for Privileged Access Detection (#4516)" (#4548) @eric-forte-elastic
- Add new ML detection rules for Privileged Access Detection (#4516) @sodhikirti07
- [FR] [DaC] Update Readme with DaC Support References (#4526) @eric-forte-elastic
- [FR] Add Env Var DR_CLI_MAX_WIDTH and DaC Docs Updates (#4518) @eric-forte-elastic
- chore: use
docs-devinstead ofdocsdir for docs (#4522) @traut - chore: adjust paths to track in REACT test CI workflow (#4498) @traut
- chore: Removing RTAs (#4437) @traut
- [Bug] [DaC] Fix Typo in CLI.md (#4491) @eric-forte-elastic
- Fix typo in error message (#4489) @shashank-elastic
- Bumping number of versions per rule to 4 in total (#4451) @traut
- Replace master doc URLs with current (#4439) @shashank-elastic
- Refresh ECS & Beats schemas, Integration manifests & schemas (#4436) @shashank-elastic
- [FR] Generate investigation guides (#4358) @Mikaayenson
🔍 Hunting Updates
- [New Hunt] Adding Hunting Queries for Azure Entra Sign-In Anomalies (#4527) @terrancedejesus
- chore: Removing RTAs (#4437) @traut
- [New Hunt] Adding hunting queries for Azure Device Code auth (#4468) @terrancedejesus
- [New Hunt] Adding Hunting Queries for AWS SNS exfiltration and data collection (#4458) @terrancedejesus
- [New Hunt] Persistence via NetworkManager Dispatcher Script (#4408) @Aegrah
- [New Hunt] Persistence via Desktop Bus (D-Bus) (#4407) @Aegrah
- [New Hunt] Persistence via PolicyKit (#4406) @Aegrah
- [New Hunt] General Kernel Manipulation (#4403) @Aegrah
- [Hunt Tuning] Fixing Sort Logic in Aviatrix Hunting Query (#4432) @terrancedejesus
- [Hunt Tuning] Logon Activity by Source IP (#4428) @Aegrah
- [New Hunt] Adding Hunting Query for
IAM Unusual Default Aviatrix Role Activity(#4409) @terrancedejesus - [New Hunt] Persistence via Initramfs (#4402) @Aegrah
- [New & Tuning] Persistence via GRUB Bootloader (#4401) @Aegrah