Skip to content

Commit 2c07e88

Browse files
authored
[Rule Tuning] Fix double bumps caused by Windows Integration Update (#4156)
1 parent 8f56b7d commit 2c07e88

File tree

293 files changed

+879
-643
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

293 files changed

+879
-643
lines changed

rules/windows/collection_email_powershell_exchange_mailbox.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/12/15"
33
integration = ["endpoint", "windows", "system", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/09/23"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/collection_winrar_encryption.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/12/04"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/command_and_control_certreq_postdata.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2023/01/13"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

rules/windows/command_and_control_dns_tunneling_nslookup.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/11"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_encrypted_channel_freesslcert.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/11/04"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/command_and_control_headless_browser.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/05/10"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_outlook_home_page.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2024/08/01"
33
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_port_forwarding_added_registry.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/11/25"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/10/10"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_rdp_tunnel_plink.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/10/14"
33
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
44
maturity = "production"
5-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
6-
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/15"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2020/09/03"
33
integration = ["endpoint", "windows", "system", "m365_defender", "sentinel_one_cloud_funnel"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
6-
min_stack_version = "8.13.0"
7-
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
5+
updated_date = "2024/10/15"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
88

99
[transform]
1010
[[transform.osquery]]

0 commit comments

Comments
 (0)