dev-v2.0.0
Note
This major version adds support for MITRE v19 mappings. These are automatically used on stack versions >= 9.5 with tags dynamically added appropriately. If you want to use the v19 mappings on stack versions <=9.4 you will need to specify DR_THREAT_MAPPING_FRAMEWORK="MITRE ATT&CK" and DR_THREAT_MAPPING_VERSION=1 or add threat_mapping_framework: "MITRE ATT&CK" and threat_mapping_version: "19" to your _config.yaml. For more details, see docs-dev/multi-version-threat-mappings.md.
Note
This is also a breaking change if you are on main and have not upgraded to a 9.5 stack. The emitted related integrations now use >= instead of ^ which is expected to not function on older stacks. Please make sure your stack schema map and/or packages.yml are set according to your stack.
Changes
- [Rule Tuning] Misc. Linux LPE Rules (#6465) @Aegrah
- [Rule Tuning] Lucene Network Rules Language Conversion (#6463) @eric-forte-elastic
- [Rule Tuning] Web Application Suspicious Activity: POST Request Declined (#6469) @eric-forte-elastic
- [New Rule/Tuning] PHP File Creation in WordPress Plugin Directory (#6473) @Aegrah
- [Rule Tuning] Accepted Default Telnet Port Connection (#6461) @eric-forte-elastic
- [Rule Tuning] Entra ID / M365 Consent Grant Suppression (#6452) @terrancedejesus
- [New Rule] Azure AKS API Server Proxying Request to Kubelet (#6428) @terrancedejesus
- [New Rule] Entra ID ROPC Authentication with Unknown Client ID (#6454) @terrancedejesus
- [New Rule] Unusual Azure VM Extension Installed; Suspicious Child Process via Azure VM CustomScript Extension (#6277) @terrancedejesus
- [Rule Tuning] AWS Discovery API Calls from VPN ASN for the First Time by Identity (#6450) @bryans3c
- [New Rule] AWS Cognito Unauthenticated Identity Pool Credentials Issued (#6443) @bryans3c
- [New Rule] AWS CloudTrail Management Events Disabled via PutEventSelectors (#6442) @bryans3c
- [New Rule] AWS GuardDuty Detection Suppression (#6441) @bryans3c
- [New Rule] AWS Attempt to Leave Organization (#6440) @bryans3c
- [New Rule] AWS Account Closed (#6438) @bryans3c
- [New Rule] AWS IAM User Console Login Without MFA (#6437) @bryans3c
- [New Rule] AWS Potential Cryptomining via ECS Task Definition Deployment (#6399) @bryans3c
- [New Rule] AWS Bedrock AgentCore Execution Role Used Outside Its Runtime (#6398) @bryans3c
- [Rule Tuning] File Creation in World-Writable Directory by Unusual Process (#6416) @Mikaayenson
- [Rule Tuning] Kernel Module Load via Built-in Utility (#6459) @Mikaayenson
- [New Rules] GCP GKE Rules Conversion Part 2 (#6430) @imays11
- [New Rule] Microsoft Defender XDR Promotion Rules (#6360) @terrancedejesus
- Update Packetbeat ML detection rules to align with the migration to the network module (#6389) @sodhikirti07
- [Rule Tuning] Severity Promotions for AWS rules (#6403) @terrancedejesus
- [Rule Tuning] Severity Promotions for Azure / Entra / M365 Rules (#6401) @terrancedejesus
- [Tuning] Ransomware over SMB rules (#6402) @Samirbous
- [New Rule] AWS Bedrock Model Prompt or Completion Containing Credentials (#6400) @bryans3c
- [Rule Tuning] Severity Promotions for GCP/GWS rules (#6404) @terrancedejesus
- [Rule Tuning] Excessive AWS S3 Object Encryption with SSE-C (#6433) @bryans3c
- [Rule Tuning] Unusual AWS S3 Object Encryption with SSE-C (#6432) @bryans3c
- [New Rules] AWS Bedrock AgentCore Runtime Prompt Credential Access (x2) + integration manifest (#6406) @bryans3c
- [Rule Tuning] Potential AWS S3 Bucket Ransomware Note Uploaded (#6434) @bryans3c
- [Rule Tuning] AWS Lambda Function URL Created with Public Access (#6412) @bryans3c
- [New Rules] GCP GKE Rule Conversions - part 1 (#6397) @imays11
- [New Rule] AWS Bedrock API Key Phantom User Activity Outside Bedrock (#6385) @bryans3c
- [New Rule] AWS Bedrock API Key Used for Destructive or Anti-Recovery Action (#6386) @bryans3c
- [New Rule] AWS IAM Credentials Added to a Bedrock API Key Phantom User (#6384) @bryans3c
- [New Rule] Entra ID Potential Conditional Access MFA Bypass via First-Party Microsoft Graph Access (#6325) @terrancedejesus
- [New Rule] Entra ID Device Registration with Phishing Kit Default OS Build (#6354) @terrancedejesus
- [New Rule] Entra ID AiTM Phishing-Kit Chain Detected (#6359) @terrancedejesus
- [Rule Tuning] Microsoft Graph Request Email Access by Unusual User and Client (#6378) @terrancedejesus
- [New Rule] Entra ID / M365 - Unusual ROPC Auth and/or Legacy Clients (#6377) @terrancedejesus
- [New Rule] Entra ID Multiple Device Registrations by a Single User (#6350) @terrancedejesus
- [New Rule] Microsoft Entra ID Impossible Travel Sign-in (#6150) @terrancedejesus
- [Rule Tuning] Entra ID OAuth Device Code Phishing via AiTM (#6358) @terrancedejesus
- [New Rules] Linux ER Rule Migrations - Part 1 (#6371) @Aegrah
- [New] GKE Kubernetes Rules (#6357) @Samirbous
- [New Rule] GenAI CLI Started with Unsafe Permission Bypass (#6232) @Mikaayenson
- [Rule Tuning] Misc GenAI Rule Tuning (#6231) @Mikaayenson
- [Rule Tuning] Windows Misc Tunings (#6379) @w0rk3r
- [Rule Tuning] First Time Seen DNS Query to RMM Domain (#6380) @w0rk3r
- [New Rule] Azure Virtual Machine Configuration Modified (#6278) @terrancedejesus
- [Tuning] Kubernetes Secret get or list from Node or Pod Service Account (#6229) @Samirbous
- [New/Tuning] DNS Tunneling via NsLookup (#6381) @Samirbous
- [New Rule] Potential ICMP Tunneling Activity to the Internet (#6352) @eric-forte-elastic
- [New Rule] ICMP Timestamp or Information Request from the Internet (#6349) @eric-forte-elastic
- [New Rule] ICMP Redirect Message from Internal Host (#6351) @eric-forte-elastic
- [New Rule] Deprecated TLS Version or Weak Cipher Negotiated Externally (#6353) @eric-forte-elastic
- [New Rule] Potential DHCP Starvation via High Client MAC Cardinality (#6355) @eric-forte-elastic
- [New Rules] Linux ER Rule Migrations - Part 2 (#6372) @Aegrah
- [New] Protected Storage Service Access via SMB (#6333) @Samirbous
- [New Rule] Potential Container Escape via Kernel core_pattern Modification (#6374) @Aegrah
- [New Rules] Duplicating Less Strict Linux LPE Rules from ER to DR (#6376) @Aegrah
- [New] Potential SQL Injection Against Microsoft SQL Server (#6364) @Samirbous
- [New] Web Server Cloud Metadata SSRF Request (#6375) @Samirbous
- [Rule Tuning/Deprecation] Linux DR Maintenance (#6373) @Aegrah
- [New Rule] Systemd Service Override Configuration File Created (#6254) @Aegrah
- [Rule Tuning] Align Microsoft Graph Email Access /me Path Predicate (#6335) @raylee-hawkins
- [Rule Tuning] First Time Seen Remote Monitoring and Management Tool (#6326) @w0rk3r
- [Rule Tuning] Credential Acquisition via Registry Hive Dumping (#6362) @w0rk3r
- [Tuning] Web Server Potential SQL Injection Request (#6365) @Samirbous
- [New Rule] AWS ECR Repository or Registry Policy Granted Public Access (#6342) @bryans3c
- [New Rule] AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content (#6347) @bryans3c
- [New Rule] AWS IAM User Console Login from Multiple Geolocations (#6348) @bryans3c
- [Rule Tuning] RDP (Remote Desktop Protocol) from the Internet (#6369) @eric-forte-elastic
- [Rule Tuning] Persistence via Suspicious Launch Agent or Launch Daemon (#6332) @Mikaayenson
- [New Rule] Splunk Enterprise PostgreSQL Sidecar Pre-Auth RCE (CVE-2026-20253) (#6279) @eric-forte-elastic
- [Rule Tuning] Multiple Alerts in Different ATT&CK Tactics on a Single Host (#6252) @Mikaayenson
- [New Rule] SMB (Windows File Sharing) Activity from the Internet (#6267) @eric-forte-elastic
- [New Rule] Potential SSH Reverse Port Forwarding (#6330) @w0rk3r
- [Rule Tuning] Multiple Remote Management Tool Vendors on Same Host (#6331) @w0rk3r
- [Rule Tuning] remove URL/IP filtering from interactive curl/wget rule (#6356) @sammonsempes
- [New Rule] AWS Backup Vault Deleted or Vault Lock Removed (#6311) @bryans3c
- [New Rule] AWS Lambda Function High-Frequency Invocation by a Single Principal (#6298) @bryans3c
- [New Rule] AWS IAM Login Profile Created or Modified for an IAM User (#6303) @bryans3c
- [Rule Tuning] Refine scope of SMTP and IPSEC NAT Rules (#6307) @eric-forte-elastic
- [New Rule] AWS IAM Account Password Policy Deleted (#6302) @bryans3c
- [New Rule] AWS IAM Inline Policy Added to a Group (#6301) @bryans3c
- [New Rule] AWS IAM Permissions Boundary Modified or Removed (#6300) @bryans3c
- [New Rule] AWS Backup Recovery Point Deleted (#6310) @bryans3c
- [New Rule] AWS Lambda Function Invoked Cross-Account (#6299) @bryans3c
- [New Rule] Azure AD Graph Access with Unusual User and ASN (#6305) @terrancedejesus
- [New Rule] AWS KMS Imported Key Material Deleted (#6304) @bryans3c
- [New Rule] AWS Lambda Function Invoked from an Unusual Source ASN (#6297) @bryans3c
- [New Rule] AWS Lambda Function Invoked by an Unusual Principal (#6296) @bryans3c
- [New] Add detection rule for AMSI bypass via RPC NdrClientCall hook (4104) (#6321) @django-88
- [New Rule] AWS Lambda Function Policy Updated to Allow Cross-Account Invocation (#6295) @bryans3c
- [New Rule] AWS Lambda Function URL Created with Public Access (#6294) @bryans3c
- [New Rule] AWS Lambda Layer Shared Externally (#6293) @bryans3c
- [New Rule] AWS Lambda Function Deletion (#6291) @bryans3c
- [New Rule] AWS Lambda Event Source Mapping Creation (#6290) @bryans3c
- [New Rule] Google Workspace Impossible Travel Login (#6148) @terrancedejesus
- [New Rule] Azure AD Graph Access with Unusual Client and User (#6182) @terrancedejesus
- [New] MS Teams Rogue Help Desk (#6322) @Samirbous
- [New Rule] Azure AD Graph 4xx Error Surge from User (#6174) @terrancedejesus
- [New] Quick Assist Full Control Sharing Mode Enabled (#6319) @Samirbous
- [New] Java Dropped and Executed With DNS Lookup (#6320) @Samirbous
- [Rule Tunings] Google Workspace Domain-Wide Delegation and First Time OAuth Login (#6281) @imays11
- [Rule: Tuning] Increase coverage for the Remote SSH Login Enabled rule (#6202) @litemars
- [Rule Tunings] Google Workspace Update Application Added and Object Copied to External Drive (#6280) @imays11
- [Rule Tunings] Google Workspace minor rule updates (#6233) @imays11
- [Rule Tunings][Rule Deprecation] Google Workspace authentication policy modification rules (#6226) @imays11
- [New Rule] Azure AD Graph Access with Suspicious User-Agent (#6175) @terrancedejesus
- [New Rule] Azure VM Managed Run Command Created or Updated with Unusual Principal (#6284) @terrancedejesus
- [New Rule] Azure VM Extension CRUD Operation with Unusual Source ASN (#6276) @terrancedejesus
- [New Rule] Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration (#6181) @terrancedejesus
- [New Rule] Azure VM Boot Diagnostics Retrieved (#6275) @terrancedejesus
- [New Rule] Azure Serial Console Connect to Virtual Machine with Unusual User and ASN (#6259) @terrancedejesus
- [Rule Tunings] Google Workspace Admin Role lifecycle rules (#6214) @imays11
- [New Rule] M365 Identity Unusual Device Code Granting (#6230) @terrancedejesus
- Add Entra ID identity attack rules: TAP creation, guest-to-member promotion, OAuth redirect URI (3 rules) (#6168) @descambiado
- [Rule Tuning] Azure Compute VM Command Executed (#6266) @terrancedejesus
- [Rule Tuning] Misc. Linux DR Tunings (#6285) @Aegrah
- [Rule Tuning] Misc. Linux DRs (#6250) @Aegrah
- [Tuning] Potential Masquerading as System32 DLL (#6286) @Samirbous
- Revert: Azure AD Graph Access with Unusual User and ASN (#6287) @Mikaayenson
- [New Rule] Azure AD Graph Access with Unusual User and ASN (#6171) @terrancedejesus
- [New Rule] Azure AD Graph Potential Enumeration (ROADrecon) (#6170) @terrancedejesus
- [New Rule] Potential Redis CONFIG SET SSH Authorized Key Injection (#6270) @eric-forte-elastic
- [New Rule] Multiple DHCP Servers Responding to the Same Transaction (#6263) @eric-forte-elastic
- [Rule Tunings] GWS Rules w/ zero alerts (#6210) @imays11
- [New Rule] Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell) (#6269) @eric-forte-elastic
- [New Rule] Potential Redis CONFIG SET Cron Directory Persistence (RedisRaider) (#6271) @eric-forte-elastic
- [Rule Tuning] Host File System Changes via Windows Subsystem for Linux (#6255) @Aegrah
- [New Rule] AWS Bedrock High-Frequency Single-Model Inference API Probing (#6256) @bryans3c
- [New Rule] AWS Bedrock Foundation Model Enumeration Followed by Invocation via Long-Term Key (#6239) @bryans3c
- [New Rule] AWS Bedrock Third-Party or External Knowledge Base Associated to Agent (#6246) @bryans3c
- [Rule Tuning] Switch AWS Bedrock Knowledge Base or RAG Data Source Poisoning to New Terms (#6257) @bryans3c
- [New Rule] AWS Bedrock Agent Created by IAM User or Root (#6242) @bryans3c
- [New Rule] AWS Bedrock Knowledge Base or RAG Data Source Poisoning (#6240) @bryans3c
- [New Rule] AWS Bedrock Resource-Based Policy Modified or Deleted & AWS Bedrock Unauthorized Resource-Based Policy Modification Attempt (#6245) @bryans3c
- [New Rule] AWS Bedrock Automated Reasoning Safety Policy Tampering (#6235) @bryans3c
- [New Rule] AWS Bedrock Guardrail Deleted or Weakened (#6236) @bryans3c
- [New Rule] AWS Bedrock Model Invocation Logging Disabled or Modified (#6237) @bryans3c
- [New Rule] AWS Bedrock Provisioned Model Throughput Tampering (#6241) @bryans3c
- [New Rule] AWS Bedrock Foundation Model Access Enabled or Entitlement Granted & AWS Bedrock Unauthorized Foundation Model Access Attempt (#6244) @bryans3c
- [New Rule] AWS Bedrock Agent or Action Group Manipulation (#6243) @bryans3c
- [New Rule] AWS Bedrock Untrusted Model Imported or Marketplace Endpoint Registered (#6247) @bryans3c
- [Rule IG Tuning] Suspicious Command Execution via Web Server (#6249) @Aegrah
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#6225) @github-actions[bot]
- [New/Tuning] Misc. Linux Web Server Rules (#6222) @Aegrah
- [New] Azure Run Command Correlated with Process Execution (#6169) @Samirbous
- [Rule Tuning] Forwarded Google Workspace Security Alert (#6166) @imays11
- [Rule Tuning] Attempt to Clear Kernel Ring Buffer (#6221) @Aegrah
- [Tuning] Diverse Recently Created Rules (#6191) @Samirbous
- [Rule Tunings] GWS Rule Tunings (small changes) (#6183) @imays11
- [New Rule] Segfault from Sensitive Process Detected (#6209) @Aegrah
- [New Rule] Entra ID / Entity Analytics ROADTools Default OS Build Fingerprint (#6193) @terrancedejesus
- [Rule Tuning] M365 Exchange Inbox Forwarding Rule Created (#6199) @terrancedejesus
- [New] Entra ID Microsoft Authentication Broker Sign-In with Non-Stand UA (#6196) @Samirbous
- [New] Entra ID Microsoft Authentication Broker DRS Sign-In from Susp ASN (#6190) @Samirbous
- [New] M365 Exchange Inbox Rule with Obfuscated Name (#6198) @Samirbous
- [New] Azure VM Extension Deployment by User (#6176) @Samirbous
- [Rule Tuning] Google Drive Ownership Transferred via Google Workspace (#6184) @imays11
- [New Rule] Google Workspace User Sign-in from Atypical Device Type (#6153) @terrancedejesus
- [New Rule] AWS S3 Credential File Retrieved from Bucket (#6197) @bryans3c
- [Rule Tuning] DNS to Commonly Abused Web Services (#6192) @Aegrah
- [New Rule] Entra ID Kali365 Default User-Agent Detected (#6194) @terrancedejesus
- [New/Tuning] Suspicious Instance Metadata Service (IMDS) API Activity (#6178) @Aegrah
- [New] Cloud Instance Metadata Credential Path HTTP Request (#6185) @Samirbous
- [Rule Tuning] Reducing FP and adding detection gap in rule Dumping Account Hashes via Built-In Commands (#6187) @litemars
- [Bug] comparison bug in rule Potential Privacy Control Bypass via TCCDB Modification (#6188) @litemars
- [Rule Tuning] Suspicious AWS S3 Connection via Script Interpreter (#6165) @shashank-elastic
- [Rule Tuning] Fix ESQL Rules with Conflicting Lookback Windows (#6179) @terrancedejesus
- [New Rule] Google Workspace Login from Atypical ASN (#6146) @terrancedejesus
- [Rule Tuning] ES|QL Explicit Null Value Removal (#6177) @eric-forte-elastic
- [Rule Tuning] Add Highlighted/Investigative Fields to M365 SharePoint Site Sharing Policy Weakened (#6157) @terrancedejesus
- [New Rule] Google Workspace Login Flagged Suspicious (BBR) (#6147) @terrancedejesus
- [New Rules] NX-Console Supply Chain Attack (#6173) @Aegrah
- [New] AWS EKS Control Plane Logging Disabled (#6100) @Samirbous
- [Rule Tuning/New Rule] Suspicious SUID Binary Execution (#6162) @Aegrah
- [Rule Tuning] Fix typo in the filename of rule Potential Persistence via Periodic Tasks (#6141) @litemars
- [Rule Tuning] Finder Sync Plugin Registered and Enabled (#6138) @litemars
- [New] Potential cPanel WHM CRLF Authentication Bypass (CVE-2026-41940) (#6102) @eric-forte-elastic
- [New] Kubernetes API Request Impersonating Privileged Identity (#6085) @Samirbous
- [New] Kubernetes Static Pod Manifest File Access (#6094) @Samirbous
- [New] Entra ID Register Device with Unusual User Agent (#6151) @Samirbous
- [New] Google Workspace Device Registration from Suspicious ASN (#6158) @Samirbous
- [New] Entra ID OAuth Device Code Phishing via AiTM (#6149) @Samirbous
- [Tuning] Diverse Rules (#6129) @Samirbous
- [New] Potential Tycoon2FA AiTM Rules (#6143) @Samirbous
- [New] Microsoft Graph Multi-Category Reconnaissance Burst (#6142) @Samirbous
- [Rule Tuning] Potential macOS SSH Brute Force Detected (#6161) @shashank-elastic
- [Tuning] LSASS Memory Dump Handle Acces (#6135) @Samirbous
- Update integrations list for problemchild detection rules (#6152) @sodhikirti07
- [Rule Tuning] File Creation in World-Writable Directory by Unusual Process (#6136) @Aegrah
- [New] Kubernetes CoreDNS or Kube-DNS Configuration Modified (#6099) @Samirbous
- [New] Kubernetes Ephemeral Container Added to Pod (#6098) @Samirbous
- [New] EKS Access Entry Granted Cluster Admin Policy (#6091) @Samirbous
- [New] EKS Authentication Configuration Modified (#6090) @Samirbous
- [New] Kubernetes API Server Proxying Request to Kubelet (#6082) @Samirbous
- [New] Kubernetes Client Certificate Signing Request Created or Approved (#6084) @Samirbous
- [Rule Tuning] First-Time FortiGate Administrator Login (#6095) @eric-forte-elastic
- [Rule Tuning] LSASS Process Access via Windows API (#6134) @dstepanic
- [Rule Tuning] Windows High-Severity Rules Revamp - Final (#6038) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 15 (#6034) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 14 (#6033) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 13 (#6032) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 12 (#6031) @w0rk3r
- [New] Kubernetes Service Account Token Created via TokenRequest API (#6077) @Samirbous
- [Rule Tuning] Suspicious macOS MS Office Child Process (#6101) @shashank-elastic
- [New] Suspicious SUID Binary Execution (Auditd Sequence) (#6104) @Samirbous
- [New/Tuning] Potential Privilege Escalation via unshare Followed by Root (#6105) @Samirbous
- [Rule Tuning] DNS Request for IP Lookup Service via Unsigned Binary (#6106) @w0rk3r
- [Rule Tuning] Windows Misc Tuning (#6088) @w0rk3r
- [Rule Tuning] M365 Atypical / Impossible Travel (geo field reliability + ApplicationId exclusion parity) (#6093) @terrancedejesus
- [New] Kubernetes Admission Webhook Created or Modified (#6078) @Samirbous
- [Rule Tuning] Network Rules Update Type and Status Field Names (#6043) @eric-forte-elastic
- [Tuning] M365 Identity Login from Impossible Travel Location (#6089) @Samirbous
- [Rule Tuning] Windows High-Severity Rules Revamp - 10 (#6028) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 11 (#6030) @w0rk3r
- [New] Container Runtime CLI Execution with Suspicious Arguments (#6009) @Samirbous
- [New] Kubernetes and Cloud Credential Path Access via Process Arguments (#6007) @Samirbous
- [Tuning] Fixing path in execution_shell_via_java_revshell_linux.toml (#6079) @yuriShafet
- [Rule Tuning] Credential access collection sensitive files (#5952) @litemars
- [New] Suspicious Kubernetes Pod Exec (#5978) @Samirbous
- [New] Potential Privilege Escalation in Container via Runc Init (#5964) @Samirbous
- [New/Tuning] Direct Kubelet API Access rules (#5996) @Samirbous
- [Rule Tuning] Windows Setup Guides - Low and Medium Severity Rules (#6042) @w0rk3r
- [New Rule] Kubernetes Pod Creation Using Common Debug or Base Images (#5890) @Aegrah
- [New Rule] DNS to Commonly Abused Web Services (#5938) @Aegrah
- [New] Sensitive Identity File Open by Suspicious Process via Auditd (#5982) @Samirbous
- [New] Kubernetes Secret get or list with Suspicious User Agent (#5974) @Samirbous
- [New/Tuning] K8 RBAC Privs (#5987) @Samirbous
- [New] Nsenter to PID 1 Namespace via Auditd/D4C (#5988) @Samirbous
- [New/Tuning] Chroot Execution in Container Context on Linux (#5992) @Samirbous
- [New] Kubernetes Secret get or list from Node or Pod Service Account (#5973) @Samirbous
- [New] Curl or Wget Execution from Container Context (#5975) @Samirbous
- [New] Kubernetes Secrets List Across Cluster or Sensitive Namespaces (#5966) @Samirbous
- [New] Kubernetes Rapid Secret GET Activity Against Multiple Objects (#5967) @Samirbous
- [New] Kubernetes Multi-Resource Discovery (#5971) @Samirbous
- [New] Unusual Process Connection to Docker or Containerd Socket (#6005) @Samirbous
- [Rule Tuning] Network Rules Deprecate Beats Indices (#5932) @eric-forte-elastic
- [Rule Tuning] Fixes for Unsupported Fields (#6025) @Aegrah
- [Rule Tuning] Misc GenAI Tuning (#6006) @Mikaayenson
- [Rule Tuning] Windows High-Severity Rules Revamp - 7 (#6013) @w0rk3r
- [Rule Tuning] Misc Windows Tuning (#5990) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 3 (#5969) @w0rk3r
- [New] Diverse AWS rules (#5913) @Samirbous
- [Rule Tuning] Windows High-Severity Rules Revamp - 5 (#6004) @w0rk3r
- [Rule Tunings] AWS ESQL keep fields missing (#6014) @imays11
- [Rule Tuning] Windows High-Severity Rules Revamp - 6 (#6010) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 8 (#6019) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 9 (#6022) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 4 (#5981) @w0rk3r
- [New] Multi-Cloud CLI Token and Credential Access Commands (#6012) @Samirbous
- [Tuning/New] Namespace Manipulation Using Unshare (#6024) @Samirbous
- Revert "[Tuning] Namespace Manipulation Using Unshare" (#5989) (#6023) @Mikaayenson
- [New] AWS Lateral Movement via Kubernetes SA (#5959) @Samirbous
- [Tuning] Namespace Manipulation Using Unshare (#5989) @Samirbous
- [New/Tuning] Linux LPE via SUID Shell (#5980) @Samirbous
- [Rule Tuning] Privilege Escalation via SUID/SGID (#6017) @Aegrah
- [Rule Tuning] Veeam Backup Library Loaded by Unusual Process (#5985) @w0rk3r
- [New] Suspicious SUID Binary Execution (#6018) @Samirbous
- [New] Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket (#6015) @eric-forte-elastic
- [Rule Tuning] Add Lunixar to RMM rules, fix new_terms condition (#5986) @w0rk3r
- [Rule Tuning] Misc Windows Tunings (#5955) @w0rk3r
- [Rule Tuning] GenAI or MCP Server Child Process Execution (#5951) @Mikaayenson
- [New] AWS Credentials Used from GitHub Actions and Non-CI/CD Infra (#5956) @Samirbous
- [New] AWS Rare Source AS Organization Activity (#5957) @Samirbous
- [Tuning] Execution via GitHub Actions Runner (#5892) @Samirbous
- [New] Long Base64 Encoded Command via Scripting Interpreter (#5891) @Samirbous
- [Rule Tuning] Additional GenAI context for Domains & Cred File Access (#5958) @Mikaayenson
- [Rule Tuning] Multiple Device Token Hashes for Single Okta Session (#5948) @terrancedejesus
- Add Entity related integrations ML rules with _ea job IDs and min_stack_version 9.4.0 (#5909) @susan-shu-c
- [New Rules] False Negatives for New BPFDoor Variants (#5939) @Aegrah
- [Rule Tuning] Update MDE tags to "Microsoft Defender XDR" (#5927) @w0rk3r
- [Rule Tuning] Abnormally Large DNS Response (#5922) @eric-forte-elastic
- [Rule Tuning] Change event.dataset to data_stream.dataset (#5943) @terrancedejesus
- [Rule Tuning] Process Created with an Elevated Token (#5934) @w0rk3r
- [Tuning] First Time Python Created a LaunchAgent or LaunchDaemon (#5937) @Samirbous
- [Tuning] Remote Management Access Launch After MSI Install (#5901) @Samirbous
- [Rule Deprecation] SUNBURST Command and Control Activity (#5928) @w0rk3r
- [Rule Tuning] Misc GenAI Rules (#5929) @Mikaayenson
- [New Rules] AWS IAM Long-Term Creds Abuse Coverage (#5924) @imays11
- Revert "[New Rules] AWS IAM Long-Term Creds Abuse Coverage" (#5923) @imays11
- [Rule Tuning] Windows High-Severity Rules Revamp - 2 (#5900) @w0rk3r
- [Rule Tuning] Windows High-Severity Rules Revamp - 1 (#5899) @w0rk3r
- [New Rules] AWS IAM Long-Term Creds Abuse Coverage (#5918) @imays11
- [New Rule] AWS S3 Rapid Bucket Posture API Calls from a Single Principal (#5911) @imays11
- [Rule Tuning] Entra ID Illicit Consent Grant via Registered Application - Fix New Terms Field (#5894) @terrancedejesus
- [Rule Tuning] M365 Identity OAuth Illicit Consent Grant by Rare Client and User (#5917) @terrancedejesus
- [Rule Tuning] Entra ID Service Principal with Unusual Source ASN (#5915) @terrancedejesus
- [Rule Tuning] Misc Windows (#5906) @w0rk3r
- [New Rule][Rule Tuning] AWS Organizations/Account Discovery Coverage (#5910) @imays11
- [Rule Tuning] AWS suspicious user agents (TruffleHog, Kali CLI/Boto3) (#5902) @terrancedejesus
- Update Entity related Kibana prebuilt ML rules with new
_eaML job ID and update minimum stack versions (#5794) @susan-shu-c - [Rule Tuning] Potential snap-confine Privilege Escalation (#5889) @Aegrah
- [New] Elastic Defend Alert from Package Manager Install Ancestry (#5905) @Samirbous
- [Rule Tuning] Curl or Wget Spawned via Node.js (#5904) @Aegrah
- [Rule Tuning] M365 Identity Login from Atypical Travel Location - Reduce FP Noise (#5866) @terrancedejesus
- [Rule Tuning] Entra ID OAuth User Impersonation to Microsoft Graph (#5864) @terrancedejesus
- [New Rules] LiteLLM & Trivy TeamPCP Compromise (#5885) @Aegrah
- [Rule Tuning] Add ICP blockchain domain indicator (#5887) @terrancedejesus
- [Rule Tuning] Python Path File (pth) Creation (#5880) @Aegrah
- [Tuning] Multiple Cloud Secrets Accessed by Source Address (#5884) @Samirbous
- [Rule Tuning] Entra ID Federation Abuse to Production (#5881) @terrancedejesus
- [Rule Tuning] M365 SharePoint/OneDrive File Access via PowerShell - Convert to new_terms (#5873) @terrancedejesus
- [Tuning] Expand compatibility to extra OS (#5883) @Samirbous
- [New] Potential Credential Discovery via Recursive Grep (#5882) @Samirbous
- [New] RMM Rules (#5848) @Samirbous
- [Rule Tuning] Sensitive Audit Policy Sub-Category Disabled (#5859) @w0rk3r
- [Rule Tuning] Misc Rule Tuning (#5858) @w0rk3r
- [Rule Tuning] M365 Exchange Inbox Forwarding Rule Created (#5852) @terrancedejesus
- [Rule Tuning] Remove OIDC email scope from Microsoft Graph Email Access Rule (#5856) @terrancedejesus
- [Rule Tuning] Microsoft Graph Request User Impersonation by Unusual Client (#5861) @terrancedejesus
- [Tuning] Add Missing executable file extensions (#5857) @Samirbous
- [New/tuning] WarLock coverage (#5846) @Samirbous
- [Tuning] Mis Rules Tuning (#5817) @Samirbous
- [New Rules] AppArmor Exploitation (CrackArmor) (#5842) @Aegrah
- [New / Tuning] LeakNet cov (#5850) @Samirbous
- [New Rules] External Promotion Alert for IBM QRadar (#5843) @Mikaayenson
- [New Rule] Potential snap-confine Privilege Escalation via CVE-2026-3888 (#5845) @Aegrah
- [Rule Tuning] Tuning Host Name to Agent Name for Compatibility (#5849) @Aegrah
- [New/Tuning] New DB Dump Rule & Tuning wget/curl DRs (#5832) @Aegrah
- [New Rule] AWS API Activity from Uncommon S3 Client by Rare User (#5694) @imays11
- [Rule Tuning] Entra ID Federated Identity Credential Issuer Modified (#5847) @terrancedejesus
- [Tuning] Connection to Commonly Abused Web Services (#5831) @Samirbous
- [Rule Tuning] Added Traefik Compatibility to Web Server Access Rules (#5837) @Aegrah
- [Rule Tuning] Dynamic Linker Copy (#5841) @Aegrah
- [New Rules] New Terms rules for malicious Python/Pickle model activity on macOS (#5780) @DefSecSentinel
- [New Rule] Azure Arc Kubernetes Cluster Connect Abuse (#5824) @terrancedejesus
- [New Rule] M365 SharePoint Site Administrator Added (#5806) @terrancedejesus
- [New Rule] AWS CloudShell Environment Created (#5830) @imays11
- [Rule Tuning] Misc GenAI Tuning (#5825) @Mikaayenson
🚀 Features
- Prep for Release 9.5 (#6474) @shashank-elastic
- [FR] Refactor Version Lock to Support Breaking Kibana Changes (Initial MITRE v19 Support) (#6367) @eric-forte-elastic
- Revert "[FR] Use ephemeral tokens" (#6464) @eric-forte-elastic
- [FR] Use ephemeral tokens (#6413) @eric-forte-elastic
- [Enhancement] Update non-ecs-schema.json to include necessary Azure platform log fields for AKS (#6418) @terrancedejesus
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#6396) @github-actions[bot]
- Monthly Manifest and Schema Refresh + investigation guides (#6387) @shashank-elastic
- [FR] Allow filter-only KQL and Indicator Match rules (#6334) @eric-forte-elastic
- [FR] Add optional user agent string for DaC commands (#6268) @eric-forte-elastic
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#6329) @github-actions[bot]
- [FR] Use >= semantic versioning for related integrations for stacks 9.5 and onwards (#6323) @eric-forte-elastic
- [Rule Tuning] Add Zeek Index Support (#6206) @eric-forte-elastic
- [FR] [DaC] Add support for Kibana workflows (#6211) @eric-forte-elastic
- Update Team Github Handle (#6227) @shashank-elastic
- Add missing guides (#6224) @shashank-elastic
- Monthly Manifest and Schema Updation and investigation guide additions (#6220) @shashank-elastic
- [Rule Tuning] Not ECS field in rule Suspicious Web Browser Sensitive File Access (#6200) @litemars
- [Rule Tuning] Abnormally Large DNS Response (#6201) @eric-forte-elastic
- [Rule Tuning] Accepted Default Telnet Port Connection (#6204) @eric-forte-elastic
- [Rule Tuning] Issue in process.args for the Potential Privilege Escalation via unshare rule (#6203) @litemars
- fix: Change bulk rule actions by updating deprecated
rule_idstoids(#5711) @IOITI - [Enhancemet] Add AADGraphActivityLogs Schema to Azure Integration for Rule Validation (#6172) @terrancedejesus
- Update Package Readme upstream (#6164) @shashank-elastic
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#6163) @github-actions[bot]
- [FR] Add explicit permissions blocks to workflows (#6145) @eric-forte-elastic
- [Rule Tuning] GitHub Private Repository Turned Public (#6131) @eric-forte-elastic
- [FR] Second Round May Dependency Updates (#6130) @eric-forte-elastic
- [FR] May Dependency Updates (#6103) @eric-forte-elastic
- ci(docs): scope pull_request triggers to integration branches (#5995) @Mpdreamz
- [FR] Merged Renovate Dependency Updates (#6008) @eric-forte-elastic
- [FR] Add new unit test for process fields in non process events (#6011) @Mikaayenson
- [FR] [DaC] Add Basic Support for Response Actions (#6083) @eric-forte-elastic
- Add Shashank as Codeowner for release workflow files (#6075) @shashank-elastic
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#6044) @github-actions[bot]
- [FR] Add sub-technique data to the summary-xlsx (#6002) @eric-forte-elastic
- [FR] [DAC] Add Exception Duplication Checking (#5689) @eric-forte-elastic
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#5998) @github-actions[bot]
- [FR] Add enforcement for deprecated_reason (#5953) @Mikaayenson
- Lock versions for releases: 8.19,9.2,9.3,9.4 (#5972) @github-actions[bot]
- Prep for Release 9.4 (#5965) @shashank-elastic
- [FR] Workflow Updates for Automatically Bumping Stack Version (#5941) @eric-forte-elastic
- [Docs] Refresh DEX Philosophy (#5933) @Mikaayenson
- [FR] [DAC] Initial Yaml Support (#5821) @eric-forte-elastic
- [FR] Load ECS mapping based on supplied stack version (#5925) @eric-forte-elastic
- Move docs workflows to elastic/docs-actions (#5897) @Mpdreamz
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5930) @github-actions[bot]
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5926) @github-actions[bot]
- Remove OSQuery/Investigate Plugin disclaimer enforcement (#5921) @w0rk3r
- [Rule Tuning] Add Supplemental Mitre Mappings (#5876) @Mikaayenson
- Lock versions for releases: 8.19,9.1,9.2,9.3 (#5888) @github-actions[bot]
- [FR] [DaC] Add fine-grained bypass env var for ES|QL
keepand metadata validation (#5869) @eric-forte-elastic - Lock versions for releases: 8.19,9.1,9.2,9.3 (#5875) @github-actions[bot]
- Add investigation guide for database dumping activity (#5871) @shashank-elastic
- [FR] Initial DaC Issue Template (#5854) @eric-forte-elastic
- [FR] Includes deprecated rule stubs to the package for upstream testing (#5813) @dplumlee
- [FR] Reset deprecated lock to the latest state during lock (#5827) @Mikaayenson
🐛 Bug Fixes
- [Bug] Fix MITRE v19 testing harness (#6470) @eric-forte-elastic
- Revert non-ecs Azure platform logs changes (#6457) @eric-forte-elastic
- [Bug] KQL does not properly escape leading forward slash (#6001) @eric-forte-elastic
- [DaC] [Bug] Raw rule loading fails when deprecated and active rules share a name (#6309) @eric-forte-elastic
- [Bug] Fix test integrations unit tests for 8.* branch (#6306) @eric-forte-elastic
- [Bug] Update Min Stack Calculation to Include Patch Version (#6289) @eric-forte-elastic
- Fix stack-dependent related_integrations.version export (#6208) @Mikaayenson
- [Bug] ESQL Remote Validation Data Stream and Patch Version Validation (#6251) @eric-forte-elastic
- [Bug] Pyright Updated Linting (#6109) @eric-forte-elastic
- [DaC] [Bug] Rule Formatter Line Wrapping Breaks Query String Filters (#6046) @eric-forte-elastic
- [FR] Add sub-technique data to the summary-xlsx (#6002) @eric-forte-elastic
- [Bug] Omit ES|QL engine columns from required_fields (#6027) @Mikaayenson
- [Bug] Lock Pyright Version (#5977) @eric-forte-elastic
- [Bug] ESQL validation support fix (#5970) @eric-forte-elastic
- [Bug] Fix Kibana version parsing for package version (#5962) @Mikaayenson
- [Bug] Small bugfix to address update navigator edge case (#5942) @eric-forte-elastic
- [Bug] KQL Validation Add Wildcard w/ Space token value (#5753) @imays11
🛠 Internal Changes
- Prep for Release 9.5 (#6474) @shashank-elastic
- [Bug] Fix MITRE v19 testing harness (#6470) @eric-forte-elastic
- [FR] Refactor Version Lock to Support Breaking Kibana Changes (Initial MITRE v19 Support) (#6367) @eric-forte-elastic
- [Enhancement] Update non-ecs-schema.json to include necessary Azure platform log fields for AKS (#6418) @terrancedejesus
- Monthly Manifest and Schema Refresh + investigation guides (#6387) @shashank-elastic
- [FR] Allow filter-only KQL and Indicator Match rules (#6334) @eric-forte-elastic
- [DaC] [Bug] Raw rule loading fails when deprecated and active rules share a name (#6309) @eric-forte-elastic
- [FR] Add optional user agent string for DaC commands (#6268) @eric-forte-elastic
- [Rule Tuning] Add Corelight support for existing rules (#6261) @eric-forte-elastic
- [Rule Tuning] Add pfSense support for existing rules (#6260) @eric-forte-elastic
- [FR] Use >= semantic versioning for related integrations for stacks 9.5 and onwards (#6323) @eric-forte-elastic
- [Bug] Fix test integrations unit tests for 8.* branch (#6306) @eric-forte-elastic
- [Bug] Update Min Stack Calculation to Include Patch Version (#6289) @eric-forte-elastic
- [FR] [DaC] Add support for Kibana workflows (#6211) @eric-forte-elastic
- Fix stack-dependent related_integrations.version export (#6208) @Mikaayenson
- [Bug] ESQL Remote Validation Data Stream and Patch Version Validation (#6251) @eric-forte-elastic
- fix: Change bulk rule actions by updating deprecated
rule_idstoids(#5711) @IOITI - [Enhancemet] Add AADGraphActivityLogs Schema to Azure Integration for Rule Validation (#6172) @terrancedejesus
- Update Package Readme upstream (#6164) @shashank-elastic
- [FR] Second Round May Dependency Updates (#6130) @eric-forte-elastic
- [Bug] Pyright Updated Linting (#6109) @eric-forte-elastic
- [FR] May Dependency Updates (#6103) @eric-forte-elastic
- [FR] Merged Renovate Dependency Updates (#6008) @eric-forte-elastic
- [FR] [DaC] Add Basic Support for Response Actions (#6083) @eric-forte-elastic
- [DaC] [Bug] Rule Formatter Line Wrapping Breaks Query String Filters (#6046) @eric-forte-elastic
- Monthly Manifest and Schema Updation (#6036) @shashank-elastic
- [FR] Add sub-technique data to the summary-xlsx (#6002) @eric-forte-elastic
- [Bug] Omit ES|QL engine columns from required_fields (#6027) @Mikaayenson
- [FR] [DAC] Add Exception Duplication Checking (#5689) @eric-forte-elastic
- [Rule Tuning] Revert Event Dataset for Security Alert Index (#5994) @terrancedejesus
- Fix value lists within exception lists (#5963) @wingiti
- [FR] Add enforcement for deprecated_reason (#5953) @Mikaayenson
- [Bug] ESQL validation support fix (#5970) @eric-forte-elastic
- Prep for Release 9.4 (#5965) @shashank-elastic
- [Bug] Fix Kibana version parsing for package version (#5962) @Mikaayenson
- [Docs] Refresh DEX Philosophy (#5933) @Mikaayenson
- [FR] [DAC] Initial Yaml Support (#5821) @eric-forte-elastic
- [Bug] Small bugfix to address update navigator edge case (#5942) @eric-forte-elastic
- [FR] Load ECS mapping based on supplied stack version (#5925) @eric-forte-elastic
- Remove OSQuery/Investigate Plugin disclaimer enforcement (#5921) @w0rk3r
- Monthly Manifest and Schema Updation (#5920) @shashank-elastic
- [New Rule] M365 Azure Monitor Alert Email with Financial or Billing Theme (#5878) @terrancedejesus
- [FR] [DaC] Add fine-grained bypass env var for ES|QL
keepand metadata validation (#5869) @eric-forte-elastic - [Bug] KQL Validation Add Wildcard w/ Space token value (#5753) @imays11
- [FR] Includes deprecated rule stubs to the package for upstream testing (#5813) @dplumlee
- [FR] Reset deprecated lock to the latest state during lock (#5827) @Mikaayenson
- [Maintenance] Update
.gitignorefor AI Artifacts (Skills, MCP, etc.) (#5833) @terrancedejesus
🔍 Hunting Updates
- [New Hunt] Mythic C2 TLS Certificate Observed in Cisco SD-WAN Exploitation (#6262) @eric-forte-elastic
- [Hunt Tuning] Entra ID Device Code Phishing / Update Drifted Docs (#5936) @terrancedejesus