Skip to content

dev-v1.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Apr 09:04
· 1301 commits to refs/heads/main since this release
80c4f7e

Changes

  • [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648) @imays11
  • Fix versions for changes in required_fileds (#4640) @shashank-elastic
  • [Rule Tuning] User Added to Privileged Group in Active Directory (#4646) @w0rk3r
  • [Rule Tuning] Replace legacy winlog.api usage (#4647) @w0rk3r
  • [New] Suspicious Azure Sign-in via Visual Studio Code (#4639) @Samirbous
  • [New] RemoteMonologue Attack rules (#4604) @Samirbous
  • [New Rule] Potential Malicious PowerShell Based on Alert Correlation (#4635) @w0rk3r
  • [Deprecate] LaunchDaemon Creation or Modification and Immediate Loading (#4547) @DefSecSentinel
  • [New Rule] Potential PowerShell Obfuscation via String Reordering (#4595) @w0rk3r
  • [Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4627) @w0rk3r
  • [New Rule] Dynamic IEX Reconstruction via Method String Access (#4634) @w0rk3r
  • [Tuning] MacOS DR Tuning PR (#4546) @DefSecSentinel
  • [New Rule] Adding Coverage for AWS CLI with Kali Linux Fingerprint Identified (#4625) @terrancedejesus
  • [New Rule] Adding Coverage for AWS IAM Virtual MFA Device Registration (#4626) @terrancedejesus
  • [New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses (#4624) @terrancedejesus
  • [Rule Tuning] Adjusting Microsoft Entra ID Rare Authentication Requirement for Principal User (#4562) @terrancedejesus
  • [Rule Tuning] Suspicious WMI Event Subscription Created (#4618) @w0rk3r
  • [Rule Tuning] SSH Authorized Keys File Deletion (#4591) @w0rk3r
  • [D4C Conversion] Converting Compatible D4C Rules to DR (#4532) @Aegrah
  • [FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529) @Aegrah
  • [Rule Tuning] Suspicious Execution via Scheduled Task (#4599) @w0rk3r
  • [Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules (#4592) @w0rk3r
  • [New] Unusual Network Connection to Suspicious Top Level Domain (#4563) @DefSecSentinel
  • [New] Unusual Network Connection to Suspicious Web Service (#4569) @DefSecSentinel
  • [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4589) @w0rk3r
  • [Tuning] Microsoft Windows Defender Tampering (#4573) @Samirbous
  • [Rule Tuning] Tuning Illicit Grant Consent Detections in Azure and M365 (#4557) @terrancedejesus
  • [Rule Tuning] Tuning Azure Conditional Access Policy Modified (#4558) @terrancedejesus
  • [Deprecation] Deprecating Azure Virtual Network Device Modified or Deleted (#4559) @terrancedejesus
  • Update Max signals value to supported limits (#4556) @shashank-elastic
  • [Rule Tuning] Added OWA (outlook for web) new AppID (#4568) @BugOrFeature
  • [Rule Tuning] Adjusting Investigation Guide for First Occurrence of Entra ID Auth via DeviceCode Protocol (#4490) @terrancedejesus

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

🔍 Hunting Updates