dev-v1.4.0
·
1026 commits
to refs/heads/main
since this release
Changes
- Delete Development Rules (#5084) @shashank-elastic
- Fix updated_date for tunings as part of #5079 (#5081) @shashank-elastic
- Tune Rules that have unsupported versions in min_stack_version (#5079) @shashank-elastic
- [Rule Tuning] Beats & Endgame Indices (#5072) @Mikaayenson
- [Rule Tuning] D-Bus Service Created (#5076) @Aegrah
- [Rule Tuning] Adjust process.code_signature.trusted condition (#5067) @w0rk3r
- [Rule Tuning] Remote File Download via PowerShell (#5062) @w0rk3r
- [Rule Tuning] Untrusted Driver Loaded (#5061) @w0rk3r
- [Rule Tuning] Connection to Commonly Abused Web Services (#5060) @w0rk3r
- Tune a Tag discrepency in rule (#5053) @shashank-elastic
- [Tuning] System File Ownership Change (#5051) @Samirbous
- [Rule Tuning] Misc. Linux ES|QL Rules (#5050) @Aegrah
- [New Rules] Potential Relay Attack against a Computer Account (#4826) @w0rk3r
- [Tuning] Unusual Network Activity from a Windows System Binary (#5048) @Samirbous
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 10 (#5025) @w0rk3r
- [New] Active Directory Discovery using AdExplorer (#5047) @Samirbous
- [New] Connection to Common Large Language Model Endpoints (#5044) @Samirbous
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 16 (#5038) @w0rk3r
- [New] Potential System Tampering via File Modification (#5043) @Samirbous
- [New/Tuning] Windows Rules to detect top threats/TTPs 24/25 (#5001) @Samirbous
- [Rule Tuning] 3rd Party EDR Compatibility - Adjust CS Windows Paths (#5037) @w0rk3r
- [Rule Tuning] Suspicious DLL Loaded for Persistence or Privilege Escalation (#5039) @w0rk3r
- [Rule Tuning] M365 Portal Logins (Impossible & Atypical) (#5031) @terrancedejesus
- [New Rule] Toolshell Exploit Chain Detections (#4928) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID Suspicious Session Reuse to Graph Access (#4997) @terrancedejesus
- [New Rule] Threat Intelligence Signal - Microsoft Defender for Office 365 (#4994) @terrancedejesus
- [Rule Tuning] Multi-Factor Authentication Disabled for User (#5006) @terrancedejesus
- [Tuning] First Occurrence of STS GetFederationToken Request by User (#5007) @imays11
- [Tuning] First Time AWS Cloudformation Stack Creation by User (#5036) @imays11
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 13 (#5028) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 15 (#5030) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 14 (#5029) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 12 (#5027) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 11 (#5026) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 9 (#5024) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 8 (#5023) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 7 (#5022) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 6 (#5021) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 5 (#5020) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 4 (#5019) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 3 (#5018) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 2 (#5017) @w0rk3r
- [Rule Tuning] Windows - Small Adjusts for Compatibility (#5032) @w0rk3r
- [Rule Tuning] Windows 3rd Party EDR Compatibility - Part 1 (#5016) @w0rk3r
- [Tuning] Unusual Network Connection to Suspicious Web Service (#5008) @Samirbous
- [Rule Tuning] First Time Seen AWS Secret Value Accessed in Secrets Manager (#4992) @imays11
- [Rule Tuning] AWS STS GetCallerIdentity API Called for the First Time (#4995) @imays11
- [New Rule] Multi-Base64 Decoding Attempt from Suspicious Location (#4931) @Aegrah
- [Rule Tuning] AWS STS AssumeRole with New MFA Device (#4999) @imays11
- [Tuning] Connection to Commonly Abused Web Services - alerts JetBrains to GH (#4973) @Samirbous
- [Rule Tuning] Suspicious Windows Powershell Arguments (#4961) @w0rk3r
- [Rule Tuning] ES|QL PowerShell Rules (#4984) @w0rk3r
- [Rule Tuning] Potential RemoteMonologue Attack (#4967) @w0rk3r
- [New] Command Line Obfuscation via Whitespace Padding (#4860) @Samirbous
- [Rule Tuning] Suspicious PrintSpooler Service Executable File Creation (#4976) @w0rk3r
- [tuning] Unusual Persistence via Services Registry (#4989) @Samirbous
- [Tuning] SDH - Investigating MFA Deactivation with no Re-Activation for Okta User Account (#4986) @imays11
- [New Rule] Potential Web Shell ASPX File Creation (#4939) @w0rk3r
- [Rule Tuning] PowerShell Script Block Logging Disabled (#4980) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Suspicious Session Reuse to Graph Access (#4954) @terrancedejesus
- [Rule Tuning] Creation or Modification of Root Certificate (#4970) @w0rk3r
- [Rule Tuning] Fixes FPs related to a process.args_count bug (#4971) @w0rk3r
- [Rule Tuning] ESQL Query Field Dynamic Field Standardization (#4912) @terrancedejesus
- [Rule Tuning] Elastic Security External Alerts (#4962) @Mikaayenson
- [Rule Tuning] AI4DSOC External Promotion Alerts (#4959) @Mikaayenson
- [New Rule] Unusual Web Config File Access (#4927) @w0rk3r
- [Rule Tuning] Script Execution via Microsoft HTML Application (#4950) @w0rk3r
- [Rule Tuning] Microsoft Azure or Mail Sign-in from a Suspicious Source (#4946) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID MFA TOTP Brute Force Attempts (#4937) @terrancedejesus
- [Rule Tuning] Azure Key Vault Secret Key Usage by Unusual Identity (#4925) @shashank-elastic
- [Rule Tuning] OIDC Discovery URL Changed in Entra ID (#4923) @Mikaayenson
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4922) @github-actions[bot]
- [New Rule] Potential Impersonation Attempt via Kubectl (#4833) @Aegrah
- [Rule Tuning] AWS EC2 AMI Shared with Another Account (#4914) @imays11
- [Rule Deprecation] Deprecated - AWS EC2 Snapshot Activity (#4913) @imays11
- [Rule Tunings] Reduce Usage of Flattened Fields in AWS Rules (#4892) @imays11
- [New Rule] OIDC Discovery URL Changed in Entra ID (#4908) @terrancedejesus
- [New Rule] Azure Key Vault Secret Key Usage by Unusual Identity (#4900) @terrancedejesus
- [New Rule] External Authentication Method Addition or Modification in Entra ID (#4906) @terrancedejesus
- [New Rule] Excessive Secret or Key Retrieval from Azure Key Vault (#4898) @terrancedejesus
- [New Rule] Kubernetes Unusual Decision by User Agent (#4829) @Aegrah
- [Rule Tuning] Azure Key Vault Modified (#4896) @terrancedejesus
- [New Rule] Unusual Kill Signal (#4911) @Aegrah
- [Rule Tuning] Sudoers File Modification (#4904) @Aegrah
- [Rule Tuning] AWS IAM API Calls via Temporary Session Tokens (#4901) @imays11
- [Rule Deprecation] Azure Virtual Network Device Modified or Deleted (#4889) @terrancedejesus
- [New Rule] TeamFiltration User-Agents Detected (#4868) @terrancedejesus
- Add investigation guides for detection rules (#4886) @shashank-elastic
- [New Rule] Suspicious Entra ID OAuth User Impersonation Scope Detected (#4876) @terrancedejesus
- [Rule Tuning] PowerShell Windows Defender ATP DataCollection Scripts (#4867) @w0rk3r
- [Rule Tuning] Windows Misc Tuning (#4870) @w0rk3r
- [New Rule] Unusual ROPC Login Attempt by User Principal (#4871) @terrancedejesus
- [New Rule] Kubectl Apply Pod from URL (#4855) @Aegrah
- [New Rule] Kubernetes Events Deleted (#4853) @Aegrah
- [Rule Tuning] Potential Linux Tunneling and/or Port Forwarding (#4858) @Aegrah
- [New Rule] Kubernetes Sensitive Configuration File Activity (#4849) @Aegrah
- [New Rule] Microsoft Entra ID Suspicious Cloud Device Registration (#4802) @terrancedejesus
🚀 Features
- [FR] Refactor Schema Validation & Support Multi-Dataset Sequence Validation (#5059) @Mikaayenson
- Fix Ruff failures (#5083) @shashank-elastic
- Add test_min_stack_version_supported testcase (#5077) @shashank-elastic
- [FR] Add negate DOES NOT MATCH capability to IM rule type (>=9.2) (#5041) @Mikaayenson
- [FR] Add support for 5 group_by fields in threshold rules (>=9.2) (#5040) @Mikaayenson
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5049) @github-actions[bot]
- Monthly Schema Updates (#5046) @shashank-elastic
- Add all rule types DaC testing (#4969) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4991) @github-actions[bot]
- Investigation guides Update (#4990) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4963) @github-actions[bot]
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4960) @github-actions[bot]
- [FR] [DAC] Add Arbitrary File location Support for Local Creation Date (#4915) @eric-forte-elastic
- [FR] Add white space checking for KQL parse (#3789) @eric-forte-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4926) @github-actions[bot]
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4924) @github-actions[bot]
- Investigation guides Update (#4920) @shashank-elastic
- Clarify authentication settings to Kibana related to #4495 (#4819) @m-a-leclercq
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#4887) @github-actions[bot]
- Prep 8.19/9.1 (#4869) @shashank-elastic
🐛 Bug Fixes
- [Bug] Incorrect Integrations Schema Parsing for Nested Fields (#5058) @eric-forte-elastic
- [Bug] Rule Toml Write Formatting Wrongly Formats \\x (#4978) @eric-forte-elastic
- [Bug] [DAC] Custom Rules Filter Discrepancy on Stacks Upgraded to 8.18 (#4945) @eric-forte-elastic
- fix: Allow different order of the metadata fields in ESQL queries (#4956) @traut
- [FR] [DAC] Add existing mitre threat information on import (#4948) @Mikaayenson
- [Bug] [DAC] Kibana Export Rules Rule Name Filter Exports All Rules (#4917) @eric-forte-elastic
- Fix variable usage impacting schema build performance (#4910) @shashank-elastic
- fix: Better aligning prompt behaviour with jsonschema types (#4894) @traut
- [FR] Updates to KQL Lib Parsing and Install (#3605) @eric-forte-elastic
- Fix pipe characters in rule descriptions (#4893) @shashank-elastic
- Bump setuptools from 75.2.0 to 78.1.1 and lock marshmallow-dataclass[union] to 8.6.1 (#4730) @dependabot[bot]
- [Bug] Fix Filter Support for Import Rules (#4852) @eric-forte-elastic
- fix: Skip invalid YAML files in Beats dist (#4865) @traut
🛠 Internal Changes
- [FR] Refactor Schema Validation & Support Multi-Dataset Sequence Validation (#5059) @Mikaayenson
- [FR] Add negate DOES NOT MATCH capability to IM rule type (>=9.2) (#5041) @Mikaayenson
- [Bug] Incorrect Integrations Schema Parsing for Nested Fields (#5058) @eric-forte-elastic
- [FR] Add support for 5 group_by fields in threshold rules (>=9.2) (#5040) @Mikaayenson
- Monthly Schema Updates (#5046) @shashank-elastic
- [Bug] Rule Toml Write Formatting Wrongly Formats \\x (#4978) @eric-forte-elastic
- [Bug] [DAC] Custom Rules Filter Discrepancy on Stacks Upgraded to 8.18 (#4945) @eric-forte-elastic
- Update latest integration manifests and schema and investigation guides (#4957) @shashank-elastic
- fix: Allow different order of the metadata fields in ESQL queries (#4956) @traut
- [FR] [DAC] Add Arbitrary File location Support for Local Creation Date (#4915) @eric-forte-elastic
- [FR] Add white space checking for KQL parse (#3789) @eric-forte-elastic
- [New Rules] External Promotion Alerts (#4903) @Mikaayenson
- [FR] [DAC] Add existing mitre threat information on import (#4948) @Mikaayenson
- [Bug] [DAC] Kibana Export Rules Rule Name Filter Exports All Rules (#4917) @eric-forte-elastic
- Fix variable usage impacting schema build performance (#4910) @shashank-elastic
- fix: Better aligning prompt behaviour with jsonschema types (#4894) @traut
- Clarify authentication settings to Kibana related to #4495 (#4819) @m-a-leclercq
- Bump setuptools from 75.2.0 to 78.1.1 and lock marshmallow-dataclass[union] to 8.6.1 (#4730) @dependabot[bot]
- [Bug] Fix Filter Support for Import Rules (#4852) @eric-forte-elastic
- Prep 8.19/9.1 (#4869) @shashank-elastic
- fix: Skip invalid YAML files in Beats dist (#4865) @traut