Skip to content

Commit 2c07e88

Browse files
authored
[Rule Tuning] Fix double bumps caused by Windows Integration Update (#4156)
1 parent 8f56b7d commit 2c07e88

File tree

293 files changed

+879
-643
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

293 files changed

+879
-643
lines changed

rules/windows/collection_email_powershell_exchange_mailbox.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/12/15"
33
integration = ["endpoint", "windows", "system", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/09/23"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/collection_winrar_encryption.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/12/04"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/command_and_control_certreq_postdata.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2023/01/13"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

rules/windows/command_and_control_dns_tunneling_nslookup.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/11"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_encrypted_channel_freesslcert.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/11/04"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/command_and_control_headless_browser.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/05/10"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_outlook_home_page.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/08/01"
33
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_port_forwarding_added_registry.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/25"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/10/10"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_rdp_tunnel_plink.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/10/14"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/09/03"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/09/03"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

rules/windows/command_and_control_remote_file_copy_scripts.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/11/29"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[transform]
810
[[transform.osquery]]

rules/windows/command_and_control_screenconnect_childproc.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/03/27"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_tunnel_vscode.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/09/09"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/09/25"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_adidns_wildcard.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2024/03/26"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_adidns_wpad_record.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2024/06/03"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_bruteforce_admin_account.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/08/29"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[transform]
810
[[transform.osquery]]

rules/windows/credential_access_bruteforce_multiple_logon_failure_followed_by_success.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/08/29"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[transform]
810
[[transform.osquery]]

rules/windows/credential_access_bruteforce_multiple_logon_failure_same_srcip.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/08/29"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[transform]
810
[[transform.osquery]]

rules/windows/credential_access_cmdline_dump_tool.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/24"
33
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/24"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

rules/windows/credential_access_credential_dumping_msbuild.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/03/25"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[transform]
810
[[transform.osquery]]

rules/windows/credential_access_dcsync_replication_rights.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2022/02/08"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_dnsnode_creation.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2024/03/26"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_dollar_account_relay.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2024/07/24"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/09"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_domain_backup_dpapi_private_keys.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/08/13"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/06/25"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_dump_registry_hives.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/23"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_generic_localdumps.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2022/08/28"
33
integration = ["endpoint", "windows", "m365_defender"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_iis_connectionstrings_dumping.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/08/18"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_imageload_azureadconnectauthsvc.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2024/10/14"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/10/14"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic", "Matteo Potito Giorgio"]

rules/windows/credential_access_kirbi_file.toml

+3-3
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2023/08/23"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/10/10"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_ldap_attributes.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2022/11/09"
33
integration = ["system", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/credential_access_lsass_handle_via_malseclogon.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2022/06/29"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

0 commit comments

Comments
 (0)