Skip to content

Commit 358a1f1

Browse files
Merge branch 'main' into 2700-bug-missing-spaces-between-logic-operators-does-not-raise-error
2 parents 96ce2da + f348e92 commit 358a1f1

File tree

31 files changed

+1338
-409
lines changed

31 files changed

+1338
-409
lines changed

detection_rules/etc/deprecated_rules.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -174,6 +174,11 @@
174174
"rule_name": "Deprecated - Container Workload Protection",
175175
"stack_version": "8.14"
176176
},
177+
"573f6e7a-7acf-4bcd-ad42-c4969124d3c0": {
178+
"deprecation_date": "2025/07/09",
179+
"rule_name": "Deprecated - Azure Virtual Network Device Modified or Deleted",
180+
"stack_version": "8.18"
181+
},
177182
"5e87f165-45c2-4b80-bfa5-52822552c997": {
178183
"deprecation_date": "2022/03/16",
179184
"rule_name": "Potential PrintNightmare File Modification",
@@ -309,6 +314,11 @@
309314
"rule_name": "Base64 Encoding/Decoding Activity",
310315
"stack_version": "7.14.0"
311316
},
317+
"98fd7407-0bd5-5817-cda0-3fcc33113a56": {
318+
"deprecation_date": "2025/07/16",
319+
"rule_name": "Deprecated - AWS EC2 Snapshot Activity",
320+
"stack_version": "8.18"
321+
},
312322
"9cf7a0ae-2404-11ed-ae7d-f661ea17fbce": {
313323
"deprecation_date": "2023/02/16",
314324
"rule_name": "Google Workspace User Group Access Modified to Allow External Access",

detection_rules/etc/non-ecs-schema.json

Lines changed: 8 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -155,28 +155,18 @@
155155
"auditd.data.a3": "keyword"
156156
},
157157
"logs-aws.cloudtrail-*": {
158-
"aws.cloudtrail.flattened.request_parameters.cidrIp": "keyword",
159-
"aws.cloudtrail.flattened.request_parameters.fromPort": "keyword",
160-
"aws.cloudtrail.flattened.request_parameters.roleArn": "keyword",
161-
"aws.cloudtrail.flattened.request_parameters.roleName": "keyword",
162-
"aws.cloudtrail.flattened.request_parameters.policyArn": "keyword",
158+
"aws.cloudtrail.flattened.request_parameters.ipPermissions.items.ipRanges.items.cidrIp": "keyword",
159+
"aws.cloudtrail.flattened.request_parameters.ipPermissions.items.fromPort": "keyword",
163160
"aws.cloudtrail.flattened.request_parameters.serialNumber": "keyword",
164161
"aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm": "keyword",
165-
"aws.cloudtrail.flattened.additional_eventdata.SSEApplied": "keyword",
166-
"aws.cloudtrail.flattened.request_parameters.bucketName": "keyword",
167-
"aws.cloudtrail.flattened.request_parameters.key": "keyword",
168162
"aws.cloudtrail.flattened.request_parameters.includeDeprecated": "keyword",
169163
"aws.cloudtrail.flattened.request_parameters.withDecryption": "boolean",
170164
"aws.cloudtrail.flattened.request_parameters.instanceId": "keyword",
171-
"aws.cloudtrail.flattened.request_parameters.dryRun": "boolean",
172-
"aws.cloudtrail.flattened.request_parameters.clientToken": "keyword",
173-
"aws.cloudtrail.flattened.response_elements.s3BucketName": "keyword",
174-
"aws.cloudtrail.flattened.response_elements.tableArn": "keyword",
175165
"aws.cloudtrail.flattened.request_parameters.attribute": "keyword",
176166
"aws.cloudtrail.flattened.request_parameters.reason": "keyword",
177167
"aws.cloudtrail.flattened.request_parameters.omitted": "keyword",
178-
"aws.cloudtrail.flattened.request_parameters.ownersSet.items.owner": "keyword",
179-
"aws.cloudtrail.flattened.response_elements.documentDescription.documentType": "keyword"
168+
"aws.cloudtrail.flattened.response_elements.documentDescription.documentType": "keyword",
169+
"aws.cloudtrail.flattened.request_parameters.groupSet.items.groupId": "keyword"
180170
},
181171
"logs-azure.signinlogs-*": {
182172
"azure.signinlogs.properties.conditional_access_audiences.application_id": "keyword",
@@ -203,6 +193,10 @@
203193
"azure.auditlogs.properties.target_resources.0.modified_properties.3.new_value": "keyword",
204194
"azure.auditlogs.properties.target_resources.0.modified_properties.2.new_value": "keyword",
205195
"azure.auditlogs.properties.additional_details.value": "keyword"
196+
},
197+
"logs-azure.platformlogs-*": {
198+
"azure.platformlogs.identity.claim.upn": "keyword",
199+
"azure.platformlogs.properties.id": "keyword"
206200
},
207201
"logs-o365.audit-*": {
208202
"o365.audit.ExtendedProperties.ResultStatusDetail": "keyword",

0 commit comments

Comments
 (0)