Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update 4.3 changelog with latest ruleset changes #11827

Merged
merged 7 commits into from Jan 20, 2022

Conversation

72nomada
Copy link
Contributor

Changelog added to ruleset:

Added

  • Added Carbanak detection rules. (#11306)
  • Added Cisco FTD rules and decoders. (#11309)
  • Added decoders for AWS EKS service. (#11284)
  • Added F5 BIG IP ruleset. (#11394)
  • Added GCP VPC Storage, Firewall and Flow rules (#11191)
  • Added Gitlab v12 ruleset. (#11323)
  • Added Microsoft Exchange Server rules and decoders. (#11289)
  • Added Microsoft Windows persistence by using registry keys detection. (#11390)
  • Added Oracle Database 12c rules and decoders. (#11274)
  • Added rules for Carbanak step 1.A - User Execution: Malicious File. (#)
  • Added rules for Carbanak step 2.A - Local Discovery. (#11212)
  • Added rules for Carbanak step 2.B - Screen Capture (#)
  • Added rules for Carbanak step 5.B - Lateral Movement via SSH. (#)
  • Added rules for Carbanak step 9.A - User Monitoring. (#11342)
  • Added rules for Cloudflare WAF. (#11373)
  • Added ruleset for ESET Remote console. (#11013)
  • Added ruleset for GITHUB audit logs. (#)
  • Added ruleset for Palo Alto v8.X - v10.X. (#11137)
  • Added SCA policy for Amazon Linux 1. (#11431)
  • Added SCA policy for Amazon Linux 2. (#11480)
  • Added SCA policy for apple macOS 10.14 Mojave. (#)
  • Added SCA policy for apple macOS 10.15 Catalina. (#)
  • Added SCA policy for macOS Big Sur. (#11454)
  • Added SCA policy for Microsoft IIS 10. (#11250)
  • Added SCA policy for Microsoft SQL 2016. (#11249)
  • Added SCA policy for Mongo Database 3.6 (#11247)
  • Added SCA policy for NGINX. (#11248)
  • Added SCA policy for Oracle Database 19c. (#11245)
  • Added SCA policy for PostgreSQL 13 (#11154)
  • Added SCA policy for SUSE Linux Enterprise Server 15. (#11223)
  • Added SCA policy for Ubuntu 14. (#11432)
  • Added SCA policy for Ubuntu 16. (#11452)
  • Added SCA policy for Ubuntu 18. (#11453)
  • Added SCA policy for Ubuntu 20. (#11430)
  • Added SCA policy for. Solaris 11.4. (#11286)
  • Added Sophos UTM Firewall ruleset. (#11122)
  • Added Wazuh-api ruleset. (#11357)

Changed

  • Updated audit rules. (#11016)
  • Updated AWS s3 ruleset. (#11177)
  • Updated Exim 4 decoder and rules to latest format. (#11344)
  • Updated MITRE DB with latest MITRE JSON specification. (#)
  • Updated multiple rules to remove alert_by_email option (#11255)
  • Updated NextCloud ruleset . (#11795)
  • Updated ProFTPD decoder. (#11232)
  • Updated RedHat Enterprise Linux 8 SCA up to version 1.0.1. (#11242)
  • Updated rules and decoders for FortiNet products. (#11100)
  • Updated SCA policy for CentOS 7. (#11429)
  • Updated SCA policy for CentOS 8. (#)
  • Updated SonicWall rules decoder. (#11263)
  • Updated SSHD ruleset. (#11388)

Fixed

  • Fixed bad character on rules 60908 and 60884 - win-application rules. (#11117)
  • Fixed Microsoft logs rules (#11369)
  • Fixed PHP rules for MITRE and groups. (#11405)
  • Fixed rules id for Microsoft Windows Powershell. (#11214)

@davidjiglesias davidjiglesias added this to the Release 4.3.0 RC 2 milestone Jan 19, 2022
@davidjiglesias davidjiglesias marked this pull request as ready for review January 20, 2022 08:46
CHANGELOG.md Outdated Show resolved Hide resolved
CHANGELOG.md Outdated Show resolved Hide resolved
CHANGELOG.md Outdated Show resolved Hide resolved
@davidjiglesias davidjiglesias merged commit 97ba155 into 4.3 Jan 20, 2022
@davidjiglesias davidjiglesias deleted the update-4.3-changelog branch January 20, 2022 08:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
No open projects
Status: Done
Development

Successfully merging this pull request may close these issues.

None yet

2 participants