dev-v1.5.0
·
946 commits
to main
since this release
Changes
- [Tuning] AWS IAM Create User via Assumed Role on EC2 Instance (#5063) @imays11
- [Rule Tunings] AWS Route Table Created / AWS EC2 Route Table Modified or Deleted (#5064) @imays11
- [Rule Tuning] SSM Session Started to EC2 Instance (#5068) @imays11
- [Rule Tuning] Potential Okta MFA Bombing via Push Notifications (#5073) @terrancedejesus
- [Rule Tuning] AWS EC2 Instance Connect SSH Public Key Uploaded (#5069) @imays11
- [Rule Tunings] AWS DynamoDB new terms Rules (#5074) @imays11
- [Tuning] AWS S3 Unauthenticated Bucket Access by Rare Source (#5075) @imays11
- [Rule Tunings] AWS SNS New Terms Rules (#5082) @imays11
- [Tuning] AWS Access Token Used from Multiple Addresses (#5055) @imays11
- [Rule Tuning] Remote Execution via File Shares (#5066) @w0rk3r
- [Rule Tuning] PowerShell Rules (#5056) @w0rk3r
- [Rule Tuning] Component Object Model Hijacking (#5065) @w0rk3r
- [Rule Tuning] Windows High Severity - 1 (#5092) @w0rk3r
- [Rule Tuning] Windows High Severity - 2 (#5093) @w0rk3r
- [Rule Tuning] Windows High Severity - 3 (#5094) @w0rk3r
- [Rule Tuning] Fix process.pe.original_file_name Conditions (#5101) @w0rk3r
- [Rule Tuning] Windows High Severity - 4 (#5095) @w0rk3r
- [Rule Tuning] Windows High Severity - 5 (#5096) @w0rk3r
- [Rule Tuning] High-Severity Noisy Rules Conversion to new_terms (#5091) @w0rk3r
- [New] Microsoft Entra ID Protection Alert and Device Registration (#4688) @Samirbous
- [New Rule] Curl or Wget Spawned via Node.js (#5132) @Aegrah
- [Rule Tuning] Mark some field optional for 3rd party compatibility (#5135) @w0rk3r
- [Rule Tuning] Suspicious PowerShell Engine ImageLoad (#5134) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Elevated Access to User Access Administrator (#5107) @terrancedejesus
- [New Rule] Credential Access via TruffleHog Execution (#5129) @Aegrah
- [New Rule] GitHub Authentication Token Access via Node.js (#5130) @Aegrah
- [New Rule] Azure Storage Account Keys Accessed by Privileged User (#5141) @terrancedejesus
- [New Rule] Node.js Pre or Post-Install Script Execution (#5131) @Aegrah
- [Rule Tuning] Updated ESQL Rules Based on Validation Results (#5151) @eric-forte-elastic
- [Rule Tuning] Potential Port Scanning Activity from Compromised Host (#5161) @Aegrah
- [Rule Tuning] Azure AD Global Administrator Role Assigned (#5090) @terrancedejesus
- [Rule Tuning] Update Azure / M365 Mappings (#5153) @terrancedejesus
- [Rule Tuning] Update Azure / M365 Index Patterns and Lookback Windows (#5155) @terrancedejesus
- [New Rules] Potential CVE-2025-32463 Exploitation (#5169) @Aegrah
- [Tuning] Potential Ransomware Behavior - High count of Readme files by System (#5167) @Samirbous
- [New] Suspicious SeIncreaseBasePriorityPrivilege Use (#5150) @Samirbous
- [Tuning] Startup or Run Key Registry Modification (#5137) @Samirbous
- [Rule Tuning] Misc. Linux Community Tunings (#5160) @Aegrah
- [New Rule] Potential CVE-2025-41244 vmtoolsd LPE Exploitation Attempt (#5166) @Aegrah
- [Rule Tuning] Unusual Instance Metadata Service (IMDS) API Request (#5163) @terrancedejesus
- [New Rule] Attempt to Clear Logs via Journalctl (#5170) @Aegrah
- [Rule Tuning] Azure Entra ID Rare App ID for Principal Authentication (#5184) @terrancedejesus
- [New Rule] Entra ID Actor Token User Impersonation Abuse (#5136) @terrancedejesus
- [New Rule] Azure Storage Account Blob Public Access Enabled (#5139) @terrancedejesus
- [New Rule] Azure RBAC Built-In Administrator Roles Assigned (#5113) @terrancedejesus
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5149) @imays11
- [Rule Tuning] AWS STS Role Chaining (#5180) @imays11
- [Rule Tuning] AWS S3 Bucket Enumeration or Brute Force (#5173) @imays11
- [Rule Tuning] Check if registry.data.strings is null on exclusion-based logic (#5193) @w0rk3r
- [Tuning] Simple HTTP Web Server Connection (#5209) @Samirbous
- [Rule Tuning] Excessive Secret or Key Retrieval from Azure Key Vault (#5220) @Mikaayenson
- [New] Potential Command Shell via NetCat (#5221) @Samirbous
- [Rule Tunings] AWS Root Access Rules (#5218) @imays11
- [Rule Tuning][Deprecation] AWS Root Console Login Rules (#5201) @imays11
🚀 Features
- Pin dependencies (#5086) @elastic-renovate-prod[bot]
- Update investigation guides (#5112) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5123) @github-actions[bot]
- Add SIEM package category (#5128) @shashank-elastic
- Monthly Schema Updates (#5187) @shashank-elastic
- Lock versions for releases: 8.18,8.19,9.0,9.1 (#5188) @github-actions[bot]
- Update Package Category (#5192) @shashank-elastic
- feat: ESQL query validation against Elastic cluster (#4955) @traut
🐛 Bug Fixes
- [Bug] Github Gist API Now Requires Auth (#5119) @eric-forte-elastic
- Added handling for unauth error (#5115) @eric-forte-elastic
- [Bug] Annotated Fields Ignored (#5125) @eric-forte-elastic
- [Bug] Add Dataclass Require Fields to the CLI Prompt (#5159) @eric-forte-elastic
- [Bug] Add unit tests and fix Alert Suppression schema validation for ThresholdQueryRuleData (#5196) @eric-forte-elastic
🛠 Internal Changes
- Bootstrap repository (#5085) @elastic-backstage-prod[bot]