dev-v1.3.0
·
1144 commits
to refs/heads/main
since this release
Rule Updates
- [New Rule] Potential Kubectl Masquerading (#4832) @Aegrah
- [New BBR] Kubectl Configuration Discovery (#4835) @Aegrah
- [New Rule] Kubectl Network Configuration Modification (#4836) @Aegrah
- [New Rule] Kubernetes Direct API Request via Curl or Wget (#4841) @Aegrah
- [New Rule] Kubernetes Forbidden Creation Request (#4843) @Aegrah
- [Rule Tunings] AWS SSM Command Document Created by Rare User (#4848) @imays11
- [Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#4854) @Samirbous
- [Deprecation] Suspicious File Creation in /etc for Persistence (#4850) @Aegrah
- [New Rule] Excessive Microsoft 365 Mailbox Items Accessed (#4825) @terrancedejesus
- [Rule Tuning] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4847) @terrancedejesus
- [New BBR] Kubectl Workload and Cluster Discovery (#4830) @Aegrah
- [New Rule] Entra ID RT to PRT Transition from Same User and Device (#4845) @terrancedejesus
- [Tuning] First Time Seen Commonly Abused Remote Access Tool Execution (#4842) @Samirbous
- [Rule Tunings] AWS Role Assumption By Service / User (#4827) @imays11
- [Rule Tuning] AWS SSM
SendCommandExecution by Rare User (#4828) @imays11 - [Rule Tuning] Suspicious Microsoft 365 Mail Access by Unusual ClientAppId (#4806) @terrancedejesus
- [Rule Tuning] First Time Seen NewCredentials Logon Process (#4844) @w0rk3r
- [Rule Tuning] Sharpening Kubernetes Rules Indices (#4822) @Aegrah
- [Rule Tuning] Added Kubernetes Domain Tag (#4831) @Aegrah
- [Tuning] Elevation via SCM rules (#4837) @Samirbous
- [New Rule] Forbidden Request from Unusual User Agent in Kubernetes (#4818) @Aegrah
- [New Rule] Suspicious ADRS Token Request by Microsoft Auth Broker (#4801) @terrancedejesus
- [New Rule] Entra ID User Signed In from Unusual Device (#4804) @terrancedejesus
- [Rule Tuning] Expand Scope of Entra ID Brute Force Sign-In Attempts (#4777) @terrancedejesus
- [Tuning] High Number of Process and/or Service Terminations" (#4813) @Samirbous
- [New Rule] Kubernetes Service Account Secret Access (#4816) @Aegrah
- [Rule Tuning] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4793) @terrancedejesus
- [New Rules] SPN Spoofing / Coercion Rules (#4815) @w0rk3r
- [Rule Tuning] AWS IAM Assume Role Policy Update (#4799) @imays11
- [Rule Tuning] AWS EC2 User Data Retrieval for EC2 Instance (#4808) @imays11
- [New Rule] AWS CloudTrail Log Evasion (#4788) @imays11
- [Rule Tuning] AWS EC2 Deprecated AMI Discovery (#4784) @imays11
- [Rule Tuning] PowerShell ES|QL Rules Tuning (#4785) @w0rk3r
- [New Rule] Kubeconfig File Creation or Modification (#4810) @Aegrah
- [New Rule] Kubeconfig File Discovery (#4811) @Aegrah
- [Rule Tuning] Container Management Utility Run Inside A Container (#4809) @Aegrah
- [New Rule] Kubectl Permission Discovery (#4812) @Aegrah
- [FN Rule Tuning] Kubernetes User Exec into Pod (#4814) @Aegrah
- [New] Potential Machine Account Relay Attack via SMB (#4803) @Samirbous
- [Rule Tuning] Outlook Home Page Registry Modification (#4798) @w0rk3r
- [Tuning] Downloaded URL Files (#4794) @Samirbous
- [New] Potential CVE-2025-33053 Exploitation (#4795) @Samirbous
- [Rule Deprecation] Azure Entra Sign-in Brute Force Microsoft 365 Accounts by Repeat Source (#4780) @terrancedejesus
- [New Rule] Microsoft Entra ID Excessive Account Lockouts Detected (#4782) @terrancedejesus
- [Tuning] Unusual Parent-Child Relationship (#4775) @Samirbous
- [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role (#4774) @imays11
- [Rule Tunings] AWS EC2 Flow Log Deletion and Network ACL Activity (#4778) @imays11
- [Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765) @Aegrah
- [Rule Tuning][New Rule][Deprecation] AWS EC2 EBS Snapshot Activity Rules (#4763) @imays11
- [New Rule] BloodHound Suite User-Agents Detected (#4769) @terrancedejesus
- [New Rule] Entra ID Protection - Risk Detection - User Risk (#4762) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID Protection Anonymized IP Risk Detection (#4759) @terrancedejesus
- [Rule Tuning] Shell Configuration Creation or Modification (#4766) @Aegrah
- [Tuning] AWS Access Token Used from Multiple Addresses (#4753) @imays11
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4756) @github-actions[bot]
- [New Rule] Microsoft 365 Suspicious Inbox Rule to Delete or Move Emails (#4743) @terrancedejesus
- [New] Disabling Lsa Protection via Registry Modification (#4747) @Samirbous
- [Rule Tuning] Tuning Azure Entra Sign-in Brute Force against Microsoft 365 Accounts (#4737) @terrancedejesus
- [New Rule] Microsoft Entra ID Elevated Access to User Access Administrator (#4742) @terrancedejesus
- [New Rule] Microsoft Entra ID User Reported Suspicious Activity (#4740) @terrancedejesus
- [Rule Tuning] Tuning Microsoft Entra ID High Risk Sign-in (#4739) @terrancedejesus
- [New] BadSuccessor dMSA Abuse Detections (#4745) @Samirbous
- [Rule Tuning] Tuning Microsoft 365 Global Administrator Role Assigned (#4738) @terrancedejesus
- [Tuning] Lateral Movement Rules (#4736) @Samirbous
- [Tuning] Account Discovery Command via SYSTEM Account (#4734) @Samirbous
- [Rule Tuning] Microsoft Graph First Occurrence of Client Request (#4728) @terrancedejesus
- [New Rule] Multiple Microsoft 365 User Account Lockouts in Short Time Window (#4717) @terrancedejesus
- [Rule Tuning] Potential Microsoft 365 User Account Brute Force (#4716) @terrancedejesus
- [New Rule] Microsoft Entra ID Protection - Risk Detections (#4725) @terrancedejesus
- [Rule Tuning] Startup or Run Key Registry Modification (#4710) @w0rk3r
- [Rule Tuning] Unusual Scheduled Task Update (#4714) @w0rk3r
- [Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4723) @Samirbous
- [Rule Tuning] Backup Deletion with Wbadmin (#4715) @w0rk3r
- [New Rule] Suspicious Email Access by First-Party Application via Microsoft Graph (#4704) @terrancedejesus
- [New Rule] Microsoft Entra Session Reuse with Suspicious Graph Access (#4711) @terrancedejesus
- [Rule Tuning] Unusual File Creation - Alternate Data Stream (#4712) @w0rk3r
- [Rule Tuning] Tuning
Suspicious Mailbox Permission Delegation in Exchange Online(#4705) @terrancedejesus - Fix new term doc broken link (#4706) @shashank-elastic
- [Rule Tuning] Add exceptions for non-interactive signin failures for Entra M365 Bruteforce (#4405) @jvalente-salemstate
- [New Rule] Unusual Exim4 Child Process (#4684) @Aegrah
- [New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683) @Aegrah
- [New Rule] Linux Telegram API Request (#4677) @Aegrah
- [Rule Tuning] Reduce Severity from Critical to High (#4637) @w0rk3r
- [New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685) @Aegrah
- [New Rule] Potential Dynamic IEX Reconstruction via Environment Variables (#4633) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Service Principal Addition Invoked by MSFT Identity (#4700) @terrancedejesus
- [New Rule] Potential PowerShell Obfuscation via Special Character Overuse (#4632) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion (#4631) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion (#4630) @w0rk3r
- [New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion (#4629) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation (#4615) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences (#4614) @w0rk3r
- [New Rule] PowerShell Obfuscation via Negative Index String Reversal (#4610) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Reverse Keywords (#4609) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction (#4608) @w0rk3r
- [New Rule] Potential PowerShell Obfuscation via String Concatenation (#4607) @w0rk3r
- [New Rule] System Binary Symlink to Suspicious Location (#4682) @Aegrah
- [New Rule] Suspicious Named Pipe Creation (#4681) @Aegrah
- [New Rule] Suspicious Kernel Feature Activity (#4676) @Aegrah
- [New Rule] Potential Data Exfiltration Through Curl (#4678) @Aegrah
- [New/Tuning] Potential Hex Payload Execution via Command-Line (#4675) @Aegrah
- [New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674) @Aegrah
- [New] Windows Sandbox with Sensitive Configuration (#4606) @Samirbous
- [New] Rare Connection to WebDAV Target (#4667) @Samirbous
- [New] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4673) @Samirbous
- [New Rule] Git Repository or File Download to Suspicious Directory (#4663) @Aegrah
- [New Rule] Manual Mount Discovery via /etc/exports (#4662) @Aegrah
- [New Rule] Docker Release File Creation (#4661) @Aegrah
- [New Rule] Manual Memory Dumping via Proc Filesystem (#4660) @Aegrah
- [FN Tuning] Suspicious /proc/maps Discovery (#4659) @Aegrah
- [New Rule] Suspicious Path Mounted (#4664) @Aegrah
- [Tuning] Connection to Commonly Abused Web Services (#4686) @Samirbous
- [New] Concurrent Azure SignIns with Suspicious Properties (#4670) @Samirbous
- [New] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4691) @Samirbous
- [New Rule] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4687) @terrancedejesus
- [New Rule] Microsoft Entra ID SharePoint Access for User Principal via Auth Broker (#4695) @terrancedejesus
- [New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658) @Aegrah
🚀 Features
- docs-builder: add
pull-requests: writepermission to docs-build workflow (#4840) @reakaleek - Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4820) @github-actions[bot]
- [FR] Update Docs for Prebuilt Rule Customization (#4787) @eric-forte-elastic
- [FR] Add Ability to Filter Rule Exports from Kibana (#4783) @eric-forte-elastic
- Update Kibana MITRE workflow (#4735) @shashank-elastic
- Add update ATT&CK coverage step in lock versions (#4772) @shashank-elastic
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4758) @github-actions[bot]
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4732) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4731) @github-actions[bot]
- Refresh MITRE version (#4729) @shashank-elastic
- Lock versions for releases: 8.14,8.15,8.16,8.17,8.18,9.0 (#4703) @github-actions[bot]
- Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4702) @github-actions[bot]
- [FR] Add check-version-lock dev command (#4650) @eric-forte-elastic
🐛 Bug Fixes
- [Bug] Makefile test-remote-cli Defined Twice (#4751) @eric-forte-elastic
- fix: Making
PyGithuba default dependency (#4744) @traut
🛠 Internal Changes
- fix: type hinting fixes and additional code checks (#4790) @traut
- [Rule Tuning] Microsoft Entra ID Exccessive Account Lockouts Detected (#4851) @terrancedejesus
- Archive Attack Coverage Update Workflow (#4821) @shashank-elastic
- [Bug] Makefile test-remote-cli Defined Twice (#4751) @eric-forte-elastic
- [FR] Update Docs for Prebuilt Rule Customization (#4787) @eric-forte-elastic
- [FR] Add Ability to Filter Rule Exports from Kibana (#4783) @eric-forte-elastic
- Refresh Integration Manifest & Schema (#4755) @shashank-elastic
- fix: Making
PyGithuba default dependency (#4744) @traut - Resolve datetime.utcfromtimestamp deprecation (#4719) @emmanuel-ferdman
- [FR] Add check-version-lock dev command (#4650) @eric-forte-elastic
- Refresh ecs, beats, integration manifests & schemas (#4699) @shashank-elastic
🔍 Hunting Updates
- fix: type hinting fixes and additional code checks (#4790) @traut
- [New Hunt] Potential Spoofed
microsoftonline.comvia Fuzzy Match (#4770) @terrancedejesus - [Bug] Makefile test-remote-cli Defined Twice (#4751) @eric-forte-elastic
- [New Hunt] Commvault Supply Chain Threat (#4748) @terrancedejesus
- [New Hunt] Microsoft Entra Infrequent Suspicious OData Client Requests (#4708) @terrancedejesus