Skip to content

Commit 28dddd9

Browse files
Merge branch 'main' into mactuner
2 parents 4f346b7 + 28a06fd commit 28dddd9

File tree

22 files changed

+44
-3
lines changed

22 files changed

+44
-3
lines changed

rules/integrations/pad/privileged_access_ml_linux_high_count_privileged_process_events_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad", "endpoint", "sysmon_linux"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_linux_high_median_process_command_line_entropy_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad", "endpoint", "sysmon_linux"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_linux_rare_process_executed_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad", "endpoint", "sysmon_linux"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_high_sum_concurrent_sessions_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_rare_host_name_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_rare_region_name_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_rare_source_ip_by_user.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_spike_in_group_application_assignment_changes.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_spike_in_group_lifecycle_changes.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/pad/privileged_access_ml_okta_spike_in_group_membership_changes.toml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ creation_date = "2025/02/18"
33
integration = ["pad","okta"]
44
maturity = "production"
55
updated_date = "2025/02/18"
6+
min_stack_version = "8.18.0"
7+
min_stack_comments = "New PAD integration only available starting at 8.18.0."
68

79
[rule]
810
anomaly_threshold = 75

0 commit comments

Comments
 (0)