Skip to content

dev-v1.3.0

Choose a tag to compare

@github-actions github-actions released this 01 Jul 13:41
· 1144 commits to refs/heads/main since this release
1fb60d6

Rule Updates

  • [New Rule] Potential Kubectl Masquerading (#4832) @Aegrah
  • [New BBR] Kubectl Configuration Discovery (#4835) @Aegrah
  • [New Rule] Kubectl Network Configuration Modification (#4836) @Aegrah
  • [New Rule] Kubernetes Direct API Request via Curl or Wget (#4841) @Aegrah
  • [New Rule] Kubernetes Forbidden Creation Request (#4843) @Aegrah
  • [Rule Tunings] AWS SSM Command Document Created by Rare User (#4848) @imays11
  • [Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#4854) @Samirbous
  • [Deprecation] Suspicious File Creation in /etc for Persistence (#4850) @Aegrah
  • [New Rule] Excessive Microsoft 365 Mailbox Items Accessed (#4825) @terrancedejesus
  • [Rule Tuning] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4847) @terrancedejesus
  • [New BBR] Kubectl Workload and Cluster Discovery (#4830) @Aegrah
  • [New Rule] Entra ID RT to PRT Transition from Same User and Device (#4845) @terrancedejesus
  • [Tuning] First Time Seen Commonly Abused Remote Access Tool Execution (#4842) @Samirbous
  • [Rule Tunings] AWS Role Assumption By Service / User (#4827) @imays11
  • [Rule Tuning] AWS SSM SendCommand Execution by Rare User (#4828) @imays11
  • [Rule Tuning] Suspicious Microsoft 365 Mail Access by Unusual ClientAppId (#4806) @terrancedejesus
  • [Rule Tuning] First Time Seen NewCredentials Logon Process (#4844) @w0rk3r
  • [Rule Tuning] Sharpening Kubernetes Rules Indices (#4822) @Aegrah
  • [Rule Tuning] Added Kubernetes Domain Tag (#4831) @Aegrah
  • [Tuning] Elevation via SCM rules (#4837) @Samirbous
  • [New Rule] Forbidden Request from Unusual User Agent in Kubernetes (#4818) @Aegrah
  • [New Rule] Suspicious ADRS Token Request by Microsoft Auth Broker (#4801) @terrancedejesus
  • [New Rule] Entra ID User Signed In from Unusual Device (#4804) @terrancedejesus
  • [Rule Tuning] Expand Scope of Entra ID Brute Force Sign-In Attempts (#4777) @terrancedejesus
  • [Tuning] High Number of Process and/or Service Terminations" (#4813) @Samirbous
  • [New Rule] Kubernetes Service Account Secret Access (#4816) @Aegrah
  • [Rule Tuning] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4793) @terrancedejesus
  • [New Rules] SPN Spoofing / Coercion Rules (#4815) @w0rk3r
  • [Rule Tuning] AWS IAM Assume Role Policy Update (#4799) @imays11
  • [Rule Tuning] AWS EC2 User Data Retrieval for EC2 Instance (#4808) @imays11
  • [New Rule] AWS CloudTrail Log Evasion (#4788) @imays11
  • [Rule Tuning] AWS EC2 Deprecated AMI Discovery (#4784) @imays11
  • [Rule Tuning] PowerShell ES|QL Rules Tuning (#4785) @w0rk3r
  • [New Rule] Kubeconfig File Creation or Modification (#4810) @Aegrah
  • [New Rule] Kubeconfig File Discovery (#4811) @Aegrah
  • [Rule Tuning] Container Management Utility Run Inside A Container (#4809) @Aegrah
  • [New Rule] Kubectl Permission Discovery (#4812) @Aegrah
  • [FN Rule Tuning] Kubernetes User Exec into Pod (#4814) @Aegrah
  • [New] Potential Machine Account Relay Attack via SMB (#4803) @Samirbous
  • [Rule Tuning] Outlook Home Page Registry Modification (#4798) @w0rk3r
  • [Tuning] Downloaded URL Files (#4794) @Samirbous
  • [New] Potential CVE-2025-33053 Exploitation (#4795) @Samirbous
  • [Rule Deprecation] Azure Entra Sign-in Brute Force Microsoft 365 Accounts by Repeat Source (#4780) @terrancedejesus
  • [New Rule] Microsoft Entra ID Excessive Account Lockouts Detected (#4782) @terrancedejesus
  • [Tuning] Unusual Parent-Child Relationship (#4775) @Samirbous
  • [Rule Tuning] AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role (#4774) @imays11
  • [Rule Tunings] AWS EC2 Flow Log Deletion and Network ACL Activity (#4778) @imays11
  • [Rule Tuning] Loadable Kernel Module Configuration File Creation (#4765) @Aegrah
  • [Rule Tuning][New Rule][Deprecation] AWS EC2 EBS Snapshot Activity Rules (#4763) @imays11
  • [New Rule] BloodHound Suite User-Agents Detected (#4769) @terrancedejesus
  • [New Rule] Entra ID Protection - Risk Detection - User Risk (#4762) @terrancedejesus
  • [Rule Tuning] Microsoft Entra ID Protection Anonymized IP Risk Detection (#4759) @terrancedejesus
  • [Rule Tuning] Shell Configuration Creation or Modification (#4766) @Aegrah
  • [Tuning] AWS Access Token Used from Multiple Addresses (#4753) @imays11
  • Update ATT&CK coverage URL(s) in docs-dev/ATT&CK-coverage.md (#4756) @github-actions[bot]
  • [New Rule] Microsoft 365 Suspicious Inbox Rule to Delete or Move Emails (#4743) @terrancedejesus
  • [New] Disabling Lsa Protection via Registry Modification (#4747) @Samirbous
  • [Rule Tuning] Tuning Azure Entra Sign-in Brute Force against Microsoft 365 Accounts (#4737) @terrancedejesus
  • [New Rule] Microsoft Entra ID Elevated Access to User Access Administrator (#4742) @terrancedejesus
  • [New Rule] Microsoft Entra ID User Reported Suspicious Activity (#4740) @terrancedejesus
  • [Rule Tuning] Tuning Microsoft Entra ID High Risk Sign-in (#4739) @terrancedejesus
  • [New] BadSuccessor dMSA Abuse Detections (#4745) @Samirbous
  • [Rule Tuning] Tuning Microsoft 365 Global Administrator Role Assigned (#4738) @terrancedejesus
  • [Tuning] Lateral Movement Rules (#4736) @Samirbous
  • [Tuning] Account Discovery Command via SYSTEM Account (#4734) @Samirbous
  • [Rule Tuning] Microsoft Graph First Occurrence of Client Request (#4728) @terrancedejesus
  • [New Rule] Multiple Microsoft 365 User Account Lockouts in Short Time Window (#4717) @terrancedejesus
  • [Rule Tuning] Potential Microsoft 365 User Account Brute Force (#4716) @terrancedejesus
  • [New Rule] Microsoft Entra ID Protection - Risk Detections (#4725) @terrancedejesus
  • [Rule Tuning] Startup or Run Key Registry Modification (#4710) @w0rk3r
  • [Rule Tuning] Unusual Scheduled Task Update (#4714) @w0rk3r
  • [Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4723) @Samirbous
  • [Rule Tuning] Backup Deletion with Wbadmin (#4715) @w0rk3r
  • [New Rule] Suspicious Email Access by First-Party Application via Microsoft Graph (#4704) @terrancedejesus
  • [New Rule] Microsoft Entra Session Reuse with Suspicious Graph Access (#4711) @terrancedejesus
  • [Rule Tuning] Unusual File Creation - Alternate Data Stream (#4712) @w0rk3r
  • [Rule Tuning] Tuning Suspicious Mailbox Permission Delegation in Exchange Online (#4705) @terrancedejesus
  • Fix new term doc broken link (#4706) @shashank-elastic
  • [Rule Tuning] Add exceptions for non-interactive signin failures for Entra M365 Bruteforce (#4405) @jvalente-salemstate
  • [New Rule] Unusual Exim4 Child Process (#4684) @Aegrah
  • [New Rule] Unusual Execution from Kernel Thread (kthreadd) Parent (#4683) @Aegrah
  • [New Rule] Linux Telegram API Request (#4677) @Aegrah
  • [Rule Tuning] Reduce Severity from Critical to High (#4637) @w0rk3r
  • [New Rule] Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments (#4685) @Aegrah
  • [New Rule] Potential Dynamic IEX Reconstruction via Environment Variables (#4633) @w0rk3r
  • [Rule Tuning] Microsoft Entra ID Service Principal Addition Invoked by MSFT Identity (#4700) @terrancedejesus
  • [New Rule] Potential PowerShell Obfuscation via Special Character Overuse (#4632) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via High Numeric Character Proportion (#4631) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion (#4630) @w0rk3r
  • [New Rule][BBR] Potential PowerShell Obfuscation via High Special Character Proportion (#4629) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation (#4615) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Invalid Escape Sequences (#4614) @w0rk3r
  • [New Rule] PowerShell Obfuscation via Negative Index String Reversal (#4610) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Reverse Keywords (#4609) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via Character Array Reconstruction (#4608) @w0rk3r
  • [New Rule] Potential PowerShell Obfuscation via String Concatenation (#4607) @w0rk3r
  • [New Rule] System Binary Symlink to Suspicious Location (#4682) @Aegrah
  • [New Rule] Suspicious Named Pipe Creation (#4681) @Aegrah
  • [New Rule] Suspicious Kernel Feature Activity (#4676) @Aegrah
  • [New Rule] Potential Data Exfiltration Through Curl (#4678) @Aegrah
  • [New/Tuning] Potential Hex Payload Execution via Command-Line (#4675) @Aegrah
  • [New Rule] Potential Backdoor Execution Through PAM_EXEC (#4674) @Aegrah
  • [New] Windows Sandbox with Sensitive Configuration (#4606) @Samirbous
  • [New] Rare Connection to WebDAV Target (#4667) @Samirbous
  • [New] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4673) @Samirbous
  • [New Rule] Git Repository or File Download to Suspicious Directory (#4663) @Aegrah
  • [New Rule] Manual Mount Discovery via /etc/exports (#4662) @Aegrah
  • [New Rule] Docker Release File Creation (#4661) @Aegrah
  • [New Rule] Manual Memory Dumping via Proc Filesystem (#4660) @Aegrah
  • [FN Tuning] Suspicious /proc/maps Discovery (#4659) @Aegrah
  • [New Rule] Suspicious Path Mounted (#4664) @Aegrah
  • [Tuning] Connection to Commonly Abused Web Services (#4686) @Samirbous
  • [New] Concurrent Azure SignIns with Suspicious Properties (#4670) @Samirbous
  • [New] Suspicious Microsoft 365 UserLoggedIn via OAuth Code (#4691) @Samirbous
  • [New Rule] Suspicious Activity via Auth Broker On-Behalf-of Principal User (#4687) @terrancedejesus
  • [New Rule] Microsoft Entra ID SharePoint Access for User Principal via Auth Broker (#4695) @terrancedejesus
  • [New Rule] Potential Linux Tunneling and/or Port Forwarding via SSH Option (#4658) @Aegrah

🚀 Features

🐛 Bug Fixes

🛠 Internal Changes

🔍 Hunting Updates