Skip to content

Releases: wazuh/wazuh-ruleset

Wazuh Ruleset 3.7.1

05 Dec 18:08
Compare
Choose a tag to compare

Added

  • New Vulnerability detector rules to warn about version comparison issues. (#237)

Wazuh Ruleset 3.7.0

10 Nov 10:48
Compare
Choose a tag to compare

Added

  • osquery: specific alerts for default packs. (#196)
  • Azure integration: Decoders and rules. (#189)

Changed

  • osquery: Rename alerts fields reference. (#196)
  • update_ruleset is not available in worker nodes. (#225)
  • Update composite rules to match only same_source_ip events. (#161)

Fixed

  • Fixed active response decoder in order to match with different dates. (#223)

Removed

  • Removed deprecated rules for Syscheck.

Wazuh Ruleset 3.6.1

07 Sep 20:16
6d53e04
Compare
Choose a tag to compare

Fixed

  • Silence rule about full disk for SNAP partitions. (#183)

Wazuh Ruleset 3.6.0

29 Aug 23:04
Compare
Choose a tag to compare

Fixed

  • Fixed login abortion log mismatch in Dovecot decoder when optional parameter didn't appear. (#171)
  • Fixed decoder for Debian packages. (#172)
  • Fixed active response decoder. (#179)

Added

  • Compatibility with TerminalServices-Gateway event type. (#175)
  • New AWS rules. (#174)

Wazuh Ruleset 3.5.0

29 Aug 19:26
53c59a5
Compare
Choose a tag to compare

Added

  • Rules for the new osquery integration.
  • Rule to ignore syscollector events.
  • CIS-CAT rules improved.
  • Rules and decoders for the new Kaspersky integration.
  • CIS rootchecks for Windows 2012 R2 (by @Bob-Andrews).
  • Extract port name for Sysmon event 3. (#127)
  • Improve Shellshock detection. (#115)

Changed

  • Decreased agent upgrade failure rules level.

Fixed

  • Windows rules: Fix SID syntax for group membership changes. (#125).
  • Windows decoders: Match "Subject :" format (#128).

Wazuh Ruleset 3.4.0

24 Jul 19:28
Compare
Choose a tag to compare

Added

  • Decoder for syscheck integration with audit.

Changed

  • Removed offset of the frequency attribute in rules. (#145)

Wazuh Ruleset 3.3.1

18 Jun 18:51
Compare
Choose a tag to compare

Added

  • Rule to detect when agents are unable to unmerge shared files. (#143)

Wazuh Ruleset 3.3.0

08 Jun 19:02
Compare
Choose a tag to compare

There are no changes for Wazuh Ruleset in this version.

Wazuh Ruleset 3.2.4

01 Jun 18:16
0ff929d
Compare
Choose a tag to compare

There are no changes for Wazuh Ruleset in this version.

Wazuh Ruleset 3.2.3

28 May 16:23
Compare
Choose a tag to compare

Added

  • GDPR (General Data Protection Regulation) mapping.
  • Improve GeoIP and composite rule support for AWS events.
  • Pfsense rules.

Fixed

  • Error handling in update ruleset script using python3.