Skip to content

Commit 252e9c6

Browse files
Updated failing rules for integrations checks
1 parent 5db426e commit 252e9c6

File tree

46 files changed

+92
-92
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

46 files changed

+92
-92
lines changed

rules/windows/command_and_control_rdp_tunnel_plink.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2020/10/14"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "system"]
44
maturity = "production"
55
min_stack_comments = "SentinelOne integration package minimum version for validation."
66
min_stack_version = "8.11.0"
7-
updated_date = "2024/05/16"
7+
updated_date = "2024/10/21"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_screenconnect_childproc.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2024/03/27"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "system"]
44
maturity = "production"
55
min_stack_comments = "SentinelOne integration package minimum version for validation."
66
min_stack_version = "8.11.0"
7-
updated_date = "2024/05/16"
7+
updated_date = "2024/10/21"
88

99

1010
[rule]

rules/windows/credential_access_cmdline_dump_tool.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2020/11/24"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/credential_access_persistence_network_logon_provider_modification.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/03/18"
3-
integration = ["endpoint", "m365_defender"]
3+
integration = ["endpoint", "m365_defender", "windows"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66

77
[transform]
88
[[transform.osquery]]

rules/windows/credential_access_relay_ntlm_auth_via_http_spoolss.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2022/04/30"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/credential_access_saved_creds_vaultcmd.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/01/19"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/credential_access_symbolic_link_to_shadow_copy_created.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/12/25"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic", "Austin Songer"]

rules/windows/credential_access_via_snapshot_lsass_clone_creation.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/11/27"
3-
integration = ["windows"]
3+
integration = ["windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/defense_evasion_disabling_windows_defender_powershell.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/07/07"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/defense_evasion_dotnet_compiler_parent_process.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2020/08/21"
3-
integration = ["endpoint", "windows"]
3+
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

0 commit comments

Comments
 (0)