dev-v1.6.0
·
547 commits
to refs/heads/main
since this release
Note
Anyone who previously used import-rules-into-repo with Kibana API exports will have exception/action connector TOML files with Kibana internal ids in metadata.rule_ids instead of rule_id UUIDs. Those items won't match in scoped exports until re-imported.
Changes
- [Rule Tuning] Entra ID OAuth Device Code Grant by Unusual User (#5791) @terrancedejesus
- [New Rule] Entra ID Domain Federation Abuse (#5809) @terrancedejesus
- [New Rule] M365 SharePoint Site Sharing Policy Weakened (#5795) @terrancedejesus
- [Tuning] First Time Seen DNS Query to RMM Domain (#5819) @Samirbous
- [Rule Tuning] AWS Access Token Used from Multiple Addresses (#5785) @imays11
- [Tuning/New] RMM Rules (#5810) @Samirbous
- [New] Suspicious Execution from VS Code Extension (#5786) @Samirbous
- [New/Tuning] TeamPCP Simulation - New & Tuned Rules (#5812) @Aegrah
- [New] Elastic Defend Alert from GenAI Utility or Descendant (#5793) @Samirbous
- [New] Potential Account Takeover - Logon from New Source IP (#5770) @Samirbous
- [Rule Tuning] Base64 Decoded Payload Piped to Interpreter (#5811) @Aegrah
- [Rule Tuning]
kubernetes.audit.userAgent-->user_agent.originalConversion (#5808) @Aegrah - [Rule Tuning] RPC (Remote Procedure Call) from the Internet (#5805) @eric-forte-elastic
- [Rule Tuning] AWS STS Role Assumption by User (#5796) @imays11
- [Rule Tuning] Unusual Process For a Windows Host - from for … (#5797) @yuriShafet
- [Tuning] LSASS Process Access via Windows API (#5807) @Samirbous
- [Rule Tuning]
agent.id-->host.idnew_termsKey Modification (#5802) @Aegrah - [Tuning] Multiple Alerts on a Host Exhibiting CPU Spike (#5789) @Samirbous
- [Rule Tunings] Add Console Session Filtering to AWS Temporary Credential Detection Rules (#5781) @imays11
- [New Rule] Microsoft 365 SharePoint/OneDrive Sensitive Search and File Access (#5777) @terrancedejesus
- [New Rule] M365 MFA Notification Email Deleted or Moved (#5779) @terrancedejesus
- [New Rule] Okta User Authentication via Proxy Followed by Security Alert (#5752) @terrancedejesus
- [Rule Tuning] M365 OneDrive/SharePoint Excessive File Downloads (#5767) @terrancedejesus
- [Rule Tuning] Telnet Authentication Bypass Rule Tuning (#5771) @eric-forte-elastic
- [Rule Tuning] Panw Rules Tuning to Support Standard Logging (#5774) @eric-forte-elastic
- [New Rule] Microsoft UAL Security-Related Building-Block Signals (#5746) @terrancedejesus
- [Rule Tuning] Entra ID Federated Identity Credential Issuer Modified (#5763) @terrancedejesus
- [Rule Tuning] Entra ID Federated Identity Credential Issuer Modified (#5760) @terrancedejesus
- [Rule Tuning] Windows Misc Tuning - 2 (#5758) @w0rk3r
- [New Rules] Kernel Discovery & BPF Load/Tampering via bpftool (#5743) @Aegrah
- [New] FortiGate SSL VPN Login Followed by SIEM Alert by User (#5757) @Samirbous
- [New/Tuning] New LKM Load Rule & FN Tuning Tunneling Rules (#5742) @Aegrah
- [Rule Tuning] Kernel Module Load via Built-in Utility (#5736) @Aegrah
- [Tuning] Newly Seen FG or Suricata alert (#5734) @Samirbous
- [Rule Tuning] LLM Completion Rules (#5744) @Mikaayenson
- [Rule Deprecation] Deprecate Individual MSFT Compliance Rules (#5679) @terrancedejesus
- [Rule Tuning] Okta Credential Stuffing, Password Spraying, and Brute Force Detection Improvements (#5723) @terrancedejesus
- [Rule Tuning] Windows Misc Tunings (#5740) @w0rk3r
- [New] Correlated Alerts on Similar User Identities (#5726) @Samirbous
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5739) @imays11
- [New] Multiple Rare Elastic Defend Behavior Rules by Host (#5738) @Samirbous
- [Rule Tuning] Entra ID Federated Identity Credential Persistence Detection (#5702) @terrancedejesus
- [Rule Tuning] Accepted Default Telnet Port Connection (#5737) @eric-forte-elastic
- [Rule Tuning] Entra ID SharePoint Accessed by Unusual User and Microsoft Authentication Broker Client (#5681) @terrancedejesus
- [Tuning] High Order Rules fine tuning (#5728) @Samirbous
- [Rule Tuning] Entra ID Suspicious Cloud Device Registration (#5683) @terrancedejesus
- [New Rule] AWS SSM Inventory Reconnaissance by Rare User (#5724) @imays11
- [New Rule] AWS Sensitive IAM Operations Performed via CloudShell (#5718) @imays11
- [New Rules] AWS IAM new identity federation provider rules (#5691) @imays11
- [Tuning] Adds host metadata to the setup requirements (#5719) @Samirbous
- [New] Potential Notepad Markdown RCE Exploitation (#5729) @Samirbous
- [Rule Tuning] PowerShell Rules Revamp - 9 (#5706) @w0rk3r
- [Rule Deprecation] M365 Teams Guest & External Access Rules (#5721) @terrancedejesus
- [Rule Tuning] Potential Timestomp in Executable Files (#5727) @w0rk3r
- [Tuning] Elastic Agent Service Terminated (#5730) @Samirbous
- [New Rule] AWS GuardDuty Member Account Manipulation (#5688) @imays11
- [Rule Tuning] M365 Identity Excessive SSO Login Errors Reported (#5677) @terrancedejesus
- [Rule Tuning] System Information Discovery via dmidecode from Parent … (#5732) @Aegrah
- [New Rule] Okta Admin Console Login Failure (#5669) @terrancedejesus
- [tuning] LLM DNS queries (#5709) @Samirbous
- [New] Elastic Defend Alert Followed by Telemetry Loss (#5716) @Samirbous
- [Rule Tuning] Okta User Assigned Administrator Role (#5671) @terrancedejesus
- [New/Tuning] Misc. D4C Rules (#5710) @Aegrah
- [Rule Deprecation] PowerShell Rules (#5707) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 8 (#5705) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 7 (#5704) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 6 (#5700) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 5 (#5699) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 4 (#5698) @w0rk3r
- [New Rule] Potential PowerShell Obfuscated Script via High Entropy (#5554) @w0rk3r
- [New/Tuning] Misc. New D4C Rules and Tunings (#5692) @Aegrah
- [Tuning/New] Solarwinds Post Exploit (#5696) @Samirbous
- [New Rule] AWS EC2 Serial Console Access Enabled (#5687) @imays11
- [Rule Tuning] Update LLM Verdict for COMPLETION Rules (#5693) @Mikaayenson
- [New] Endpoint Rule Conversion PR (#5658) @DefSecSentinel
- [Rule Tuning] Adding D4C Compatibility to Compatible Container-Related Rules (#5685) @Aegrah
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#5657) @imays11
- [Rule Tuning] Machine Learning Detected a Suspicious Windows Event (#5686) @yuriShafet
- MacOS detection rules tuning (#5667) @DefSecSentinel
- [New Rules] Misc. K8s RBAC Abuse Rules (#5673) @Aegrah
- [Tuning] M365 Exchange Inbox Phishing Evasion Rule Created (#5648) @Samirbous
- [Rule Tuning] Dormant & Deprecated Rule Clean-Up (#5672) @Aegrah
- [New Rules] ESQL LLM-Based Alert Triage Rules (#5656) @Mikaayenson
- [New Rule] Execution via OpenClaw Agent (#5666) @Mikaayenson
- [Rule Tuning] Unsigned DLL Side-Loading from a Suspicious Folder: Add Downloads path and fix subdirectory evasion (#5592) @ailiffa
- [New] SolarWinds Web Help Desk Java Module Load or Child Process (#5665) @Samirbous
- [Tuning] M365 Exchange Inbox Forwarding Rule Created (#5647) @Samirbous
- [Tuning] Component Object Model Hijacking (#5651) @Samirbous
- [Tuning] Svchost spawning Cmd (#5649) @Samirbous
- [New] Multiple Machine Learning Alerts by Influencer Field (#5660) @Samirbous
- [Rule Tuning] Full Kubernetes Ruleset (#5659) @Aegrah
- [New Rules] Misc. D4C Rules re: (un)Authenticated API Access (#5661) @Aegrah
- [Rule Tuning] Mythic C2 AzureBlob Profile Endpoints (#5663) @terrancedejesus
- [New Rule] Fortigate (FG-IR-26-060) Detections (#5641) @terrancedejesus
- [Rule Tuning] M365 Security Compliance Potential Ransomware Activity (#5653) @terrancedejesus
- [Tuning] Hosts File Modified (#5655) @Samirbous
- [New Rule] Okta AiTM Session Cookie Replay Detection (#5627) @terrancedejesus
- [New] Suspicious FortiGate and Fortinet Logon rules (#5640) @Samirbous
- [New] Newly Observed Process Exhibiting CPU Spike (#5635) @Samirbous
- chore: Fix lock version for 9.3.2 Release (#5634) @eric-forte-elastic
- [Rule Tuning] Accepted Default Telnet Port Connection (#5629) @eric-forte-elastic
- [Rule Tuning] PowerShell Rules Revamp - 2 (#5623) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 3 (#5625) @w0rk3r
- [Rule Tuning] PowerShell Rules Revamp - 1 (#5619) @w0rk3r
- [New] Multiple Alerts on a Host Exhibiting CPU Spike (#5621) @Samirbous
- [Rule Tuning] Entra ID OAuth Phishing via First-Party Microsoft Application (#5610) @terrancedejesus
- [New] Detection Alert on a Process Exhibiting CPU Spike (#5617) @Samirbous
- [New] Multiple Vulnerabilities by Asset via Wiz (#5598) @Samirbous
- [Tuning] ESQL Dynamic unique value fields (#5569) @Samirbous
- [New] Lateral Movement Alerts from a Newly Observed Entity (#5557) @Samirbous
- [Rule Tuning] Several Community DR Issues (#5615) @Aegrah
- [New/Tuning] General API Abuse D4C/K8s Rules (#5591) @Aegrah
- [New Rule] Curl SOCKS Proxy Detected via Defend for Containers (#5596) @Aegrah
- [New Rules] Reintroduction of Defend for Containers (D4C) Ruleset (#5561) @Aegrah
- [Tuning] Multiple Cloud Secrets Accessed by Source Address (#5618) @Samirbous
- Revert "[Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578)" (#5620) @Mikaayenson
- [Tuning] Potential Ransomware Behavior - Note Files by System (#5595) @Samirbous
- [Tuning] Rare Connection to WebDAV Target (#5604) @Samirbous
- [Rule Tuning] Adding D4C Compatibility to Compatible K8s-related Rules (#5578) @Aegrah
- [New] Potential Telnet Authentication Bypass (CVE-2026-24061) (#5612) @Samirbous
- [Rule Tuning] Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource (#5589) @terrancedejesus
- [Rule Tuning] Entra ID OAuth Device Code Flow with Concurrent Sign-ins (#5594) @terrancedejesus
- [Rule Tuning] M365 Threat Intelligence Signal (#5587) @terrancedejesus
- [New] Newly Observed Network Alert (#5585) @Samirbous
- [Tuning] Suricata and Elastic Defend Network Correlation (#5583) @Samirbous
- [Tuning] Rare Connection to WebDAV Target (#5556) @Samirbous
- [Rule Tuning] Removing
host.os.typefrom K8s Rules (#5577) @Aegrah - [Rule Tunings] AWS remove target.entity.id and actor.entity.id fields (#5603) @imays11
- [New] Potential SAP NetWeaver Exploitation rules (#4666) @Samirbous
- reverting 07579f2 (#5602) @terrancedejesus
- [Rule Tunings] AWS remove target.entity.id and actor.entity.id fields (#5563) @imays11
- [Rule Deprecations] AWS Rule Deprecations (#5568) @imays11
- [Rule Tunings] AWS Removing Disclaimer from IGs (#5567) @imays11
- [Rule Tuning] Web Server Rules (#5581) @w0rk3r
- [Rule Tuning] Potential Disabling of AppArmor - Restore AppArmor serv… (#5574) @ailiffa
- [Rule Tuning] Potential Network Scan Detected (#5571) @w0rk3r
- [Tuning] Reduce NewTerm history_window_start for Windows Rules (#5560) @Samirbous
- Docs: improve WinRAR/7-Zip encrypted archive rule guidance (#5547) @gustavo89587
- [New Rules] Ollama Detections (#5546) @Mikaayenson
- [Rule Deprecation] Agent Spoofing - Mismatched Agent ID (#5552) @w0rk3r
- [Rule Tuning] Okta Sign-In Events via Third-Party IdP - Convert to New Terms (#5544) @terrancedejesus
- [New] Multiple Alerts in Same ATT&CK Tactic by Host (#5550) @Samirbous
- [Rule Tuning] New Okta Authentication Behavior Detected (#5542) @terrancedejesus
- [New Rule] ConsentFix Detections (#5485) @terrancedejesus
- [Tuning] Multiple Cloud Secrets Accessed by Source Address (#5549) @Samirbous
- [Rule Tuning] Entra ID Protection Sign-in and User Risk Detection Rules - Filter Remediated Risk States (#5535) @terrancedejesus
- [New] Multiple External EDR Alerts by Host (#5540) @Samirbous
- [Rule Tuning] GenAI DR Tuning (#5506) @Mikaayenson
- [New] First Time Seen Elastic Defend Behavior Alert (#5528) @Samirbous
- [New] Potential Persistence via Mandatory User Profile (#5530) @Samirbous
- [Tuning] Process Created with an Elevated Token (#5532) @Samirbous
- [Tuning] SMB (Windows File Sharing) Activity to the Internet (#5533) @Samirbous
- [New Rules] Several GitHub Related Rules (#5470) @Aegrah
- [New/Tuning] Several New Linux Rules (#5531) @Aegrah
- [New Rule] Potential Password Spraying Attack via SSH (#5515) @Aegrah
- [Rule Tuning] Linux DR Tuning - 3 (#5483) @Aegrah
- [Rule Tuning] Linux DR Tuning - 7 (#5504) @Aegrah
- [Rule Tuning] Linux DR Tuning - 6 (#5497) @Aegrah
- [Rule Tuning] Linux DR Tuning - 4 (#5484) @Aegrah
- [Rule Tuning] Linux DR Tuning - 8 (#5505) @Aegrah
- [Rule Tuning] Linux DR Tuning - 10 (#5510) @Aegrah
- [Tuning] Suspicious DLL Loaded for Persistence or Privilege Escalation (#5525) @Samirbous
- [Rule Tuning] Entra ID Excessive Account Lockouts Detected (#5502) @terrancedejesus
- [New] Suspected Lateral Movement from Compromised Host (#5521) @Samirbous
- [Rule Tuning] Linux DR BBR Tuning (#5514) @Aegrah
- [Rule Tuning] Linux DR CP Tuning (#5512) @Aegrah
- [Rule Tuning] Linux DR Tuning - 11 (#5511) @Aegrah
- [Rule Tuning] Linux DR Tuning - 9 (#5508) @Aegrah
- [Rule Tuning] Linux DR Tuning - 5 (#5494) @Aegrah
- [Rule Tuning] Linux DR Tuning - 2 (#5481) @Aegrah
- [Rule Tuning] Linux DR Tuning - 1 (#5122) @Aegrah
- [Tuning] Web Shell Detection: Script Process Child of Common Web Processes" (#5524) @Samirbous
- [New] Multiple Elastic Defend Alerts from Single Process Tree (#5522) @Samirbous
- [Tuning] Elastic Defend and Network Security Alerts Correlation (#5518) @Samirbous
- [Tuning] Suspicious React Server Child Process (#5503) @Samirbous
- [Rule Tuning] Entra ID OAuth PRT Issuance to Non-Managed Device Detected (#5464) @terrancedejesus
- [Rule Tuning] Entra ID User Sign-in with Unusual Registered Device (#5466) @terrancedejesus
- [Rule Tuning] AWS Service Quotas Multi-Region GetServiceQuota Requests (#5468) @imays11
- [Rule Tuning] AWS SQS Queue Purge (#5457) @imays11
- [Rule Tunings] AWS Config Rule Tunings (#5456) @imays11
- [Rule Tunings] AWS Lambda Rules (#5451) @imays11
- [Rule Tuning] AWS EC2 EBS Snapshot Access Removed (#5499) @imays11
- [Rule Tuning] Multiple Alerts Involving a User (#5498) @w0rk3r
- [Rule Tuning] Potential Network Scan Detected (#5495) @w0rk3r
- [Rule Tuning] Shared Object Created or Changed by Previously Unknown … (#5469) @Aegrah
- [New] React2Shell Network Security Alert (#5445) @Samirbous
- [New] Suricata and Elastic Defend Network Correlation (#5443) @Samirbous
- [Rule Tuning] Entra ID User Sign-in with Unusual Client (#5473) @terrancedejesus
- [Rule Tuning] Entra ID OAuth user_impersonation Scope for Unusual User and Client (#5462) @terrancedejesus
- [Rule Tuning] AWS EventBridge Rule Disabled or Deleted (#5458) @imays11
- [Rule Tuning] AWS CLI with Kali Linux Fingerprint Identified (#5467) @imays11
- [Rule Tunings] AWS Route 53 Rules (#5448) @imays11
- [New] Alerts From Multiple Integrations by Entity (#5460) @Samirbous
- [Rule Tunings] AWS New Terms History Window Reduction (#5479) @imays11
- [Rule Tunings] AWS WAF Rules (#5429) @imays11
- [Tuning] Top Noisy Windows BBR (#5480) @Samirbous
- [Tuning] Diverse Rules Tuning (#5482) @Samirbous
- [New Rule] GitHub Actions Bot Pushed to Repository for First Time (#5438) @terrancedejesus
- [Docs] Fix Docs Unit Test (#5496) @w0rk3r
- [Rule Tuning] PowerShell Rules - Misc Tuning/Severity Bumps (#5486) @w0rk3r
- [Rule Tuning] Communication App Rules (#5487) @w0rk3r
- [New Rule] GitHub Actions Workflow Injection Blocked (#5433) @terrancedejesus
- [Tuning] Elastic Defend and Email Alerts Correlation (#5459) @Samirbous
- [New/Tuning] Linux Tunneling Rules (#5452) @Aegrah
- [Rule Tuning] Security File Access via Common Utilities (#5453) @Aegrah
- [Tuning] Suspicious Kerberos Authentication Ticket Request (#5455) @Samirbous
- [Tuning] Agent Spoofing - Multiple Hosts Using Same Agent (#5446) @Samirbous
- [Tuning] Renamed Utility Executed with Short Program Name (#5454) @Samirbous
- [Tuning] Top Noisy Rules (#5449) @Samirbous
- [Rule Tuning] Suspicious Network Connection via systemd (#5432) @Aegrah
- [Rule Tuning] Unusual Web Server Command Execution (#5450) @Aegrah
- [Tuning] Suspicious React Server Child Process (#5447) @Samirbous
- [Rule Tuning] Update Azure / M365 Rule Names and File Paths (#5172) @terrancedejesus
- [Rule Tuning] New GitHub Self Hosted Action Runner (#5436) @terrancedejesus
- [Rule Tuning] Add Missing Metadata to KEEP conditions (#5442) @w0rk3r
- [Rule Tuning] Potential Masquerading as Svchost (#5439) @w0rk3r
- [Rule Tuning] Microsoft Entra ID Excessive Account Lockouts Detected (#5424) @terrancedejesus
- [Rule Tuning] Remove New Wiz Defend Rule (Add Wiz Defend to External Alerts) (#5422) @terrancedejesus
- [Rule Tuning] AWS RDS DB Snapshot Shared with Another Account (#5418) @imays11
- [Rule Tuning] AWS KMS Customer Managed Key Disabled or Scheduled for Deletion (#5417) @imays11
- [Rule Tunings] AWS S3 Bucket Replicated to Another Account | AWS S3 Bucket Policy Added to Share with External Account (#5405) @imays11
- [Rule Tunings] AWS Multiple API Calls ESQL rules (#5238) @imays11
- [Rule Tuning] Creation or Modification of Pluggable Authentication Mo… (#5421) @Aegrah
- Update lateral_movement_scheduled_task_target.toml to fix null values (#5228) @theusername-sudo
- [New Rule] Wiz Defend Promotion Alerts (#5410) @terrancedejesus
- [Tuning] Potential Masquerading as Svchost" (#5416) @Samirbous
- [Rule Tuning] Suspicious React Server Child Process (#5419) @Aegrah
- [New Rule] React2Shell Detection (#5408) @terrancedejesus
- [Tuning] Rare Connection to WebDAV Target (#5415) @Samirbous
- [New Rule] AWS EC2 LOLBin Execution via SSM (#5354) @terrancedejesus
- [Rule Tuning] AWS STS AssumeRoot by Rare User and Member Account (#5398) @imays11
- [Rule Tuning] AWS S3 Object Encryption Using External KMS Key (#5399) @imays11
- [Rule Tuning] AWS Access Token Used from Multiple Addresses (#5412) @imays11
- [Rule Tuning] Interval fix + Datastream values to ESQL Rules (#5413) @Aegrah
- [Rule Tuning] Update PowerShell ES|QL Rules KEEP Condition (#5391) @w0rk3r
- [Tuning] Suspicious React Child Process (#5414) @Samirbous
- [Rule Tuning] Potential Persistence via File Modification (#5404) @Aegrah
- [New Rule] Web Server Potential Remote File Inclusion Activity (#5394) @Aegrah
- [New Rule] Web Server Local File Inclusion Activity (#5393) @Aegrah
- [New] Suspicious React Server Child Process (#5407) @Samirbous
- [New] Multiple Cloud Secrets Accessed by Source Address (#5388) @Samirbous
- [New Rule] Potential HTTP Downgrade Attack (#5372) @Aegrah
- [New Rule] Initial Access via File Upload Followed by GET Request (#5371) @Aegrah
- [Rule Tuning] Node.js Pre or Post-Install Script Execution to Cross-Platform (#5403) @terrancedejesus
- [New] Suspicious Microsoft Entra ID Concurrent Sign-Ins via DeviceCode (#5396) @Samirbous
- [Rule Tuning] M365 OneDrive Excessive File Downloads with OAuth Token (#5365) @terrancedejesus
- [Rule Deprecation] AWS Redshift Cluster Creation (#5367) @imays11
- [Rule Tuning] AWS IAM Brute Force of Assume Role Policy (#5282) @imays11
- [New Rule] Unusual Web Server Command Execution (#5392) @Aegrah
- [New Rule] Pod or Container Creation with Suspicious Command-Line (#5379) @Aegrah
- [Rule Tuning] Python Startup Hook Rules (#5400) @Aegrah
- [Rule Tuning] AWS EFS File System Deleted (#5369) @imays11
- [Rule Tunings] AWS RDS Rules (#5366) @imays11
- [Rule Tuning] Potential PowerShell Obfuscated Script (#5389) @w0rk3r
- [New/Tuning] NPM Shai-Hulud coverage (#5368) @Samirbous
- [New Rule] Web Server Potential SQL Injection Request (#5342) @Aegrah
- [New Rule] Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners (#5370) @Aegrah
- [Rule Tuning] File Deletion via Shred (#5381) @Aegrah
- [Rule Tuning] At Job Created or Modified (#5378) @Aegrah
- [New Rule] Potential Secret Scanning via Gitleaks (#5377) @Aegrah
- [New Rule] Privileged Container Creation with Host Directory Mount (#5373) @Aegrah
- [Rule Tuning] Persistence via a Windows Installer (#5386) @w0rk3r
- [Rule Tuning] Potential System Tampering via File Modification (#5385) @w0rk3r
- [Rule Tuning] Windows Misc Tuning (#5382) @w0rk3r
- [Tuning] Elastic Defend and Network Security Alerts Correlation (#5375) @Samirbous
- [Tuning] Powershell Atomics test gaps for T1059.001 (#5380) @Samirbous
- [Rule Tuning] Host File System Changes via Windows Subsystem for Linux (#5383) @w0rk3r
- [Tuning] Suspicious Kerberos Authentication Ticket Request (#5364) @Samirbous
- Add rules for Azure Activity Logs/GCP Audit ML jobs (#5191) @jmcarlock
- [Rule Tuning] Credential Access via TruffleHog Execution (#5362) @Aegrah
- [New Rule] Webshell Deployed via Apache Struts CVE-2023-50164 Exploitation (#5345) @terrancedejesus
- [New Rule] Okta Multiple OS Names Detected for a Single DT Hash (#5241) @terrancedejesus
- [Rule Tuning] Microsoft Entra ID Exccessive Account Lockouts (#5315) @terrancedejesus
- [Rule Tuning] Potential Spike in Web Server Error Logs (#5359) @eric-forte-elastic
- [New Rule] Web Server Potential Command Injection Request (#5341) @Aegrah
- [New Rule] Web Server Suspicious User Agent Request Spike (#5340) @Aegrah
- [New Rule] Web Server Unusual Spike in Error Logs (#5339) @Aegrah
- [New Rule] Web Server Unusual Spike in Error Response Codes (#5338) @Aegrah
- [New Rule] Web Server Discovery or Fuzzing Activity (#5337) @Aegrah
- [New] Alerts in Different ATT&CK Tactics by Host (#5343) @Samirbous
- [New] Elastic Defend and Email Alerts Correlation (#5336) @Samirbous
- [New] Elastic Defend and Network Security Alerts Correlation (#5332) @Samirbous
- [Rule Tunings] AWS IAM Roles Anywhere Rules (#5307) @imays11
- [Rule Tuning] AWS GuardDuty Detector Deletion (#5309) @imays11
- [Rule Tunings] AWS CloudWatch Deletion Rules (#5316) @imays11
- [Rule Tuning] Rapid Secret Retrieval Attempts from AWS SecretsManager (#5291) @imays11
- [Rule Tuning] AWS IAM API Calls via Temporary Session Tokens (#5310) @imays11
- [Rule Deprecations] AWS RDS Lifecycle Rules and Outdated APIs (#5350) @imays11
- [Deprecation] Deprecated - AWS Root Login Without MFA (#5351) @imays11
- [New Rule] Proxy Shell Execution via Busybox (#5348) @Aegrah
- [New Rule] Curl or Wget Egress Network Connection via LoLBin (#5347) @Aegrah
- [New] PANW Command and Control Correlation (#5331) @Samirbous
- [New] SOCKS Traffic from an Unusual Process (#5324) @Samirbous
- [Tuning] Agent Spoofing - Multiple Hosts Using Same Agent (#5313) @Samirbous
- [Deprecations] AWS Elasticache Security Group Rules (#5334) @imays11
- [New] Potential Masquerading as Svchost (#5305) @Samirbous
- [Rule Tuning] Remote File Creation in World Writeable Directory (#5304) @Aegrah
- [Rule Tuning] AWS IAM CompromisedKeyQuarantine Policy Attached to User (#5281) @imays11
- [Rule Tuning] AWS EC2 Instance Console Login via Assumed Role (#5285) @imays11
- [Rule Tuning] AWS IAM SAML Provider Updated (#5284) @imays11
- [Rule Tunings] AWS IAM Virtual MFA Device Rules (#5275) @imays11
- [Rule Tuning] Potential Execution via XZBackdoor (#5318) @Aegrah
- [New Rule] Azure Compute Snapshot Deletion(s) (#5211) @terrancedejesus
- [Security Content] Windows Setup Guides - WinEventLog & Sysmon (#5162) @w0rk3r
- [Rule Tuning] Remove
host.os.typeUnit Test Forwarded Events Exception (#5317) @w0rk3r - [Rule Tuning] AWS GetSessionToken Abuse (#5274) @imays11
- [Rule Tunings] AWS Cloudtrail Created/Updated/Suspended/Deleted (#5292) @imays11
- [Rule Tunings] AWS Group Creation, User Added to Group, Group Deletion (#5269) @imays11
- [Rule Tuning] AWS S3 Bucket Configuration Deletion (#5265) @imays11
- [New] Command Obfuscation via Unicode Modifier Letters (#5311) @Samirbous
- [Rule Tuning] Azure Diagnostic Settings Deletion (#5253) @terrancedejesus
- [Tuning] Agent Spoofing - Mismatched Agent ID (#5312) @Samirbous
- [New Rule] Potential Git CVE-2025-48384 Exploitation (#5301) @Aegrah
- [Rule Tuning] Elastic Agent Service Terminated (#5272) @alstolten
- [Rule Tuning] Microsoft 365 Global Administrator Role Assigned (#5293) @terrancedejesus
- MITRE ATT&CK Sub-Technique Update - Solves Issue #5279 (#5280) @veritasr3x
- [New] New USB Storage Device Mounted (#5299) @Samirbous
- [New Rule] Potential SSH Password Grabbing via strace (#5294) @Aegrah
- [Rule Tunings] AWS Bedrock Rules (#5296) @Mikaayenson
- [Tuning] Potential Ransomware Behavior - Note Files by System (#5235) @Samirbous
- [New] Windows Server Update Service Spawning Suspicious Processes (#5250) @Samirbous
- [Rule Tunings] AWS EC2 EBS Snapshot and Encryption Rules (#5229) @imays11
- [Tuning] Agent Spoofing - Mismatched Agent ID (#5295) @shashank-elastic
- [Rule Tuning] AWS S3 Bucket Server Access Logging Disabled (#5254) @imays11
- [Rule Tuning] AWS S3 Bucket Expiration Lifecycle Configuration Added (#5251) @imays11
- [New Rule][Deprecation] AWS EC2 Export Task Rules (#5248) @imays11
- [Rule Tuning] AWS EC2 Full Network Packet Capture Detected (#5244) @imays11
- [Rule Tuning] File Transfer or Listener Established via Netcat (#5223) @Aegrah
- [Rule Tuning] Adds Crowdstrike Compatibility to Linux Process Rules (#5232) @Aegrah
- [New Rule] Privilege Escalation via SUID/SGID Proxy Execution (#5266) @Aegrah
- [Rule Tuning] AWS S3 Object Versioning Suspended (#5261) @imays11
- [Rule Tuning] AWS S3 Static Site Javascript File Uploaded (#5264) @imays11
- [Rule Tuning][New Rule] AWS S3 Bucket Policy Added to Share with External Account/ to Allow Public Access (#5268) @imays11
- [Rule Tuning] M365 Impossible / Atypical Travel FN (#5267) @terrancedejesus
- [New] Suspicious Kerberos Authentication Ticket Request (#5260) @Samirbous
- [New Rule] Azure Compute Restore Point Collection Deleted (#5217) @terrancedejesus
- [New Rule] Azure Storage Account Deletion (#5200) @terrancedejesus
- [New Rule] Azure Recovery Services Deletion (#5214) @terrancedejesus
- [Rule Tuning] Suspicious Entra ID OAuth User Impersonation Scope Detected (#5190) @terrancedejesus
- [Rule Tuning] Potential CVE-2025-32463 Sudo Chroot Execution Attempt (#5227) @Aegrah
- [New Rule] Entra ID Protection Admin Confirmed Compromise (#5186) @terrancedejesus
- [Rule Tuning] AWS User Created Access Keys For Another User (#5212) @imays11
- [Rule Tuning][New BBR Rule] AWS Sign-In Token Creation and Console Login (#5197) @imays11
- [Rule Tunings] AWS IAM Administrator Access Policy Attached to Group/Role/User (#5215) @imays11
- [New Rule] Azure Storage Blob Retrieval via AzCopy (#5179) @terrancedejesus
🚀 Features
- [FR] Bump minor version (#5822) @eric-forte-elastic
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5820) @github-actions[bot]
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5818) @github-actions[bot]
- Monthly Manifest and Schema Updation (#5816) @shashank-elastic
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5765) @github-actions[bot]
- [FR] Add deprecated file to release for upstream testing (#5749) @Mikaayenson
- [FR] Add copilot instructions to catch the gotchas (#5733) @Mikaayenson
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5708) @github-actions[bot]
- Monthly Manifest and Schema Updation (#5697) @shashank-elastic
- (chore): Update owners (#5675) @Mikaayenson
- [doc fix] Adjust wording in the docs for Kibana import/export commands (#5600) @traut
- Add
securityproduct to docset.yml (#5654) @reakaleek - Lock versions for releases: 8.19,9.1,9.2,9.3 (#5639) @github-actions[bot]
- Add investigation guides (#5630) @shashank-elastic
- Added logic to main.py to use the created_at and updated_at values if they exist (#5444) @aarju
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5553) @github-actions[bot]
- Prep for Release 9.3 (#5548) @shashank-elastic
- [FR] Update stale.yml Bot (#5434) @Mikaayenson
- Lock versions for releases: 8.19,9.0,9.1,9.2 (#5426) @github-actions[bot]
- [New Rules] Add MITRE ATLAS framework support and GenAI threat detection rules (#5352) @Mikaayenson
- [FR] Expand CUSTOM_RULES_DIR to support user relative paths (#5390) @eric-forte-elastic
- Add MITRE ATT&CK threat mappings for ML job rules (#5333) @jmcarlock
- Lock versions for releases: 8.19,9.0,9.1,9.2 (#5360) @github-actions[bot]
- Add Investigation Guides for Rules (#5357) @shashank-elastic
- Renovate Updates (#5258) @shashank-elastic
- Lock versions for releases: 8.19,9.0,9.1,9.2 (#5300) @github-actions[bot]
- Refresh Manifest and Schemas November Update (#5298) @shashank-elastic
- Update tj-actions/changed-files action to v46.0.5 (#5097) @elastic-renovate-prod[bot]
- Update Release Fleet to use ESQL Remote Validation (#5245) @shashank-elastic
- [FR] Add ESQL rules to dataset exception (#5249) @eric-forte-elastic
- Add unit test for protected prebuilt-rules (#5242) @shashank-elastic
- [FR] ESQL Validation Remove TOML Filtering for PR Workflow (#5243) @eric-forte-elastic
- Lock versions for releases: 8.19,9.0,9.1,9.2 (#5234) @github-actions[bot]
- Prep 9.2 (#5231) @shashank-elastic
🐛 Bug Fixes
- [Bug] [DAC] Add filtering to export-rules-from-repo (#5769) @eric-forte-elastic
- [Bug] Ignore Other Keep Wildcards (#5792) @eric-forte-elastic
- [Bug]
test_integration_tagincorrectly flags higher-order rules using.alerts-security.*index (#5783) @terrancedejesus - [Bug] ES|QL Validation Add Reverse Lookup Check Against Kibana Value (#5747) @eric-forte-elastic
- [Bug] CLI adds frequency field to system actions (.cases), causing import failure (#5690) @eric-forte-elastic
- [Bug] ESQL validation keep Clause Reported Missing Metadata Fields (#5717) @eric-forte-elastic
- [Bug] Fix UTF-8 Encoding for Rule File Operations (#5684) @Aegrah
- Ignore Keep * for ES|QL hash calc (#5638) @eric-forte-elastic
- [Bug] Test Remote CLI Update Test Indices (#5632) @eric-forte-elastic
- [fix] Preserve
actions[].params.messagefield formatting during rule export from the repo (#5597) @traut - [Bug] Update Docs Token Reference (#5562) @eric-forte-elastic
- [Bug] Importing rules from directory uses wrong type (#5428) @eric-forte-elastic
- [Rule Tunings] Misc. Web Server Rules (#5384) @Aegrah
- Skip unit test for protected prebuilt-rules on DAC env (#5323) @shashank-elastic
- [Tuning] Outbound Scheduled Task Activity via PowerShell (#5287) @Samirbous
- [Bug] Add synthetic properties check to remote ESQL validation (#5308) @eric-forte-elastic
- [Bug] [DAC] Auto Gen Schema Fails on Certain Subqueries (#5256) @eric-forte-elastic
- Update Splunk Schemas for pre-release versions to support 9.0 Kibana (#5233) @shashank-elastic
🛠 Internal Changes
- [Bug] [DAC] Add filtering to export-rules-from-repo (#5769) @eric-forte-elastic
- [Bug] Ignore Other Keep Wildcards (#5792) @eric-forte-elastic
- Monthly Manifest and Schema Updation (#5816) @shashank-elastic
- [FR] Minor Typo Fixes (#5784) @eric-forte-elastic
- [Bug] Adding Deprecated Rules to Rules Package Breaks Current Package Build (#5773) @terrancedejesus
- [Bug] ES|QL Validation Add Reverse Lookup Check Against Kibana Value (#5747) @eric-forte-elastic
- [FR] Add deprecated file to release for upstream testing (#5749) @Mikaayenson
- [Bug] CLI adds frequency field to system actions (.cases), causing import failure (#5690) @eric-forte-elastic
- [Bug] ESQL validation keep Clause Reported Missing Metadata Fields (#5717) @eric-forte-elastic
- Monthly Manifest and Schema Updation (#5697) @shashank-elastic
- [Bug] Fix UTF-8 Encoding for Rule File Operations (#5684) @Aegrah
- [doc fix] Adjust wording in the docs for Kibana import/export commands (#5600) @traut
- Add
securityproduct to docset.yml (#5654) @reakaleek - README fixes (#5616) @traut
- Ignore Keep * for ES|QL hash calc (#5638) @eric-forte-elastic
- [fix] Preserve
actions[].params.messagefield formatting during rule export from the repo (#5597) @traut - Added logic to main.py to use the created_at and updated_at values if they exist (#5444) @aarju
- [FR] Add keep metadata check to esql schema test (#5441) @eric-forte-elastic
- Prep for Release 9.3 (#5548) @shashank-elastic
- [Bug] Importing rules from directory uses wrong type (#5428) @eric-forte-elastic
- December Schema Refresh (#5420) @shashank-elastic
- [New Rules] Add MITRE ATLAS framework support and GenAI threat detection rules (#5352) @Mikaayenson
- [FR] Expand CUSTOM_RULES_DIR to support user relative paths (#5390) @eric-forte-elastic
- [FR] ES|QL remote validation support newline split indices (#5356) @eric-forte-elastic
- Renovate Updates (#5258) @shashank-elastic
- [Bug] Add synthetic properties check to remote ESQL validation (#5308) @eric-forte-elastic
- [Bug] [DAC] Auto Gen Schema Fails on Certain Subqueries (#5256) @eric-forte-elastic
- Refresh Manifest and Schemas November Update (#5298) @shashank-elastic
- [FR] Add ESQL rules to dataset exception (#5249) @eric-forte-elastic
- Prep 9.2 (#5231) @shashank-elastic
🔍 Hunting Updates
- [FR] Minor Typo Fixes (#5784) @eric-forte-elastic