Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bc6 rule import april 9 #63152

Merged
merged 3 commits into from
Apr 10, 2020
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that rarely uses the network could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_network_activity_ecs",
"name": "Unusual Linux Network Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that rarely uses the network could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_network_port_activity_ecs",
"name": "Unusual Linux Network Port Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that rarely uses the network could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_network_service",
"name": "Unusual Linux Network Service",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A new and unusual program or artifact download in the course of software upgrades, debugging, or troubleshooting could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_network_url_activity_ecs",
"name": "Unusual Linux Web Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_process_all_hosts_ecs",
"name": "Anomalous Process For a Linux Population",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Uncommon user activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "linux_anomalous_user_name_ecs",
"name": "Unusual Linux Username",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"DNS domains that use large numbers of child domains, such as software or content distribution networks, can trigger this signal and such parent domains can be excluded."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "packetbeat_dns_tunneling",
"name": "DNS Tunneling",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal. Network activity that occurs rarely, in small quantities, can trigger this signal. Possible examples are browsing technical support or vendor networks sparsely. A user who visits a new or unique web destination may trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "packetbeat_rare_dns_question",
"name": "Unusual DNS Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Web activity that occurs rarely in small quantities can trigger this signal. Possible examples are browsing technical support or vendor URLs that are used very sparsely. A user who visits a new and unique web destination may trigger this signal when the activity is sparse. Web applications that generate URLs unique to a transaction may trigger this when they are used sparsely. Web domains can be excluded in cases such as these."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "packetbeat_rare_server_domain",
"name": "Unusual Network Destination Domain Name",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Web activity that occurs rarely in small quantities can trigger this signal. Possible examples are browsing technical support or vendor URLs that are used very sparsely. A user who visits a new and unique web destination may trigger this signal when the activity is sparse. Web applications that generate URLs unique to a transaction may trigger this when they are used sparsely. Web domains can be excluded in cases such as these."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "packetbeat_rare_urls",
"name": "Unusual Web Request",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Web activity that is uncommon, like security scans, may trigger this signal and may need to be excluded. A new or rarely used program that calls web services may trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "packetbeat_rare_user_agent",
"name": "Unusual Web User Agent",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "rare_process_by_host_linux_ecs",
"name": "Unusual Process For a Linux Host",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "rare_process_by_host_windows_ecs",
"name": "Unusual Process For a Windows Host",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Security audits may trigger this signal. Conditions that generate bursts of failed logins, such as misconfigured applications or account lockouts could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "suspicious_login_activity_ecs",
"name": "Unusual Login Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that rarely uses the network could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_network_activity_ecs",
"name": "Unusual Windows Network Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A new and unusual program or artifact download in the course of software upgrades, debugging, or troubleshooting could trigger this signal. Users downloading and running programs from unusual locations, such as temporary directories, browser caches, or profile paths could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_path_activity_ecs",
"name": "Unusual Windows Path Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_process_all_hosts_ecs",
"name": "Anomalous Process For a Windows Population",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Users running scripts in the course of technical support operations of software upgrades could trigger this signal. A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_process_creation",
"name": "Anomalous Windows Process Creation",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Certain kinds of security testing may trigger this signal. PowerShell scripts that use high levels of obfuscation or have unusual script block payloads may trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_script",
"name": "Suspicious Powershell Script",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"A newly installed program or one that runs rarely as part of a monthly or quarterly workflow could trigger this signal."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_service",
"name": "Unusual Windows Service",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Uncommon user activity can be due to an administrator or help desk technician logging onto a workstation or server in order to perform manual troubleshooting or reconfiguration."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_anomalous_user_name_ecs",
"name": "Unusual Windows Username",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Uncommon user privilege elevation activity can be due to an administrator, help desk technician, or a user performing manual troubleshooting or reconfiguration."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_rare_user_runas_event",
"name": "Unusual Windows User Privilege Elevation Activity",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
"false_positives": [
"Uncommon username activity can be due to an engineer logging onto a server instance in order to perform manual troubleshooting or reconfiguration."
],
"from": "now-16m",
"from": "now-45m",
"interval": "15m",
"machine_learning_job_id": "windows_rare_user_type10_remote_login",
"name": "Unusual Windows Remote User",
Expand Down