dev-v1.1.0
·
1301 commits
to refs/heads/main
since this release
Changes
- [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4648) @imays11
- Fix versions for changes in required_fileds (#4640) @shashank-elastic
- [Rule Tuning] User Added to Privileged Group in Active Directory (#4646) @w0rk3r
- [Rule Tuning] Replace legacy winlog.api usage (#4647) @w0rk3r
- [New] Suspicious Azure Sign-in via Visual Studio Code (#4639) @Samirbous
- [New] RemoteMonologue Attack rules (#4604) @Samirbous
- [New Rule] Potential Malicious PowerShell Based on Alert Correlation (#4635) @w0rk3r
- [Deprecate] LaunchDaemon Creation or Modification and Immediate Loading (#4547) @DefSecSentinel
- [New Rule] Potential PowerShell Obfuscation via String Reordering (#4595) @w0rk3r
- [Rule Tuning] Potential DLL Side-Loading via Trusted Microsoft Programs (#4627) @w0rk3r
- [New Rule] Dynamic IEX Reconstruction via Method String Access (#4634) @w0rk3r
- [Tuning] MacOS DR Tuning PR (#4546) @DefSecSentinel
- [New Rule] Adding Coverage for
AWS CLI with Kali Linux Fingerprint Identified(#4625) @terrancedejesus - [New Rule] Adding Coverage for
AWS IAM Virtual MFA Device Registration(#4626) @terrancedejesus - [New Rule] Adding Coverage for AWS Temporary User Session Token Used from Multiple Addresses (#4624) @terrancedejesus
- [Rule Tuning] Adjusting
Microsoft Entra ID Rare Authentication Requirement for Principal User(#4562) @terrancedejesus - [Rule Tuning] Suspicious WMI Event Subscription Created (#4618) @w0rk3r
- [Rule Tuning] SSH Authorized Keys File Deletion (#4591) @w0rk3r
- [D4C Conversion] Converting Compatible D4C Rules to DR (#4532) @Aegrah
- [FN Tuning] Shared Object Created or Changed by Previously Unknown Pr… (#4529) @Aegrah
- [Rule Tuning] Suspicious Execution via Scheduled Task (#4599) @w0rk3r
- [Rule Tuning] Add Host Metadata to ES|QL Aggregation Rules (#4592) @w0rk3r
- [New] Unusual Network Connection to Suspicious Top Level Domain (#4563) @DefSecSentinel
- [New] Unusual Network Connection to Suspicious Web Service (#4569) @DefSecSentinel
- [Rule Tuning] O365 Exchange Suspicious Mailbox Right Delegation (#4589) @w0rk3r
- [Tuning] Microsoft Windows Defender Tampering (#4573) @Samirbous
- [Rule Tuning] Tuning Illicit Grant Consent Detections in Azure and M365 (#4557) @terrancedejesus
- [Rule Tuning] Tuning
Azure Conditional Access Policy Modified(#4558) @terrancedejesus - [Deprecation] Deprecating
Azure Virtual Network Device Modified or Deleted(#4559) @terrancedejesus - Update Max signals value to supported limits (#4556) @shashank-elastic
- [Rule Tuning] Added OWA (outlook for web) new AppID (#4568) @BugOrFeature
- [Rule Tuning] Adjusting Investigation Guide for
First Occurrence of Entra ID Auth via DeviceCode Protocol(#4490) @terrancedejesus
🚀 Features
- fix: Cleaning up the hashable content for the rule (#4621) @traut
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4649) @github-actions[bot]
- [Enhancement] Add flag to export rules via KQL search on name (#4594) @frederikb96
- [FR] Add Support for Local Dates Flag (#4582) @eric-forte-elastic
- [FR] Add Kibana Action Connector Error to Exception List Workaround (#4583) @eric-forte-elastic
- [FR] Update Detection Rules MITRE Workflow to SHA Pin (#4581) @eric-forte-elastic
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4601) @github-actions[bot]
- Add investigation guides (#4600) @shashank-elastic
- [maintenance] Update docset.yml (#4590) @Mikaayenson
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4571) @github-actions[bot]
- Prep main for 9.1 (#4555) @shashank-elastic
- [Bug] Update Custom Rules Markdown Location (#4565) @eric-forte-elastic
- Create new detection rule set documentation to be included in the new docs. (#4508) @Mpdreamz
🐛 Bug Fixes
- [Bug] Update Schema Prompt to include new_terms_fields (#4567) @eric-forte-elastic
🛠 Internal Changes
- fix: Cleaning up the hashable content for the rule (#4621) @traut
- Add 8.18 and 9.0 beats schemas (#4641) @shashank-elastic
- [New Rule] Threat Intel Email Indicator Match (#4598) @w0rk3r
- [Bug] Update Schema Prompt to include new_terms_fields (#4567) @eric-forte-elastic
- [Enhancement] Add flag to export rules via KQL search on name (#4594) @frederikb96
- Feature exclude tactic name (#4593) @frederikb96
- [FR] Add Support for Local Dates Flag (#4582) @eric-forte-elastic
- [FR] Add Kibana Action Connector Error to Exception List Workaround (#4583) @eric-forte-elastic
- Remove Task List reference (#4605) @shashank-elastic
- [maintenance] Update docset.yml (#4590) @Mikaayenson
- Prep main for 9.1 (#4555) @shashank-elastic
- [Bug] Update Custom Rules Markdown Location (#4565) @eric-forte-elastic
- Create new detection rule set documentation to be included in the new docs. (#4508) @Mpdreamz
🔍 Hunting Updates
- [New Hunt] New Hunting Queries for DPRK ByBit (#4644) @terrancedejesus
- [Rule Tuning] Tuning
Azure Service Principal Credentials Added(#4570) @terrancedejesus