Skip to content

Commit 7138225

Browse files
Lock versions for releases: 8.19,9.1,9.2,9.3 (#5639)
(cherry picked from commit 8b8c0be)
1 parent da80f5c commit 7138225

File tree

4 files changed

+747
-352
lines changed

4 files changed

+747
-352
lines changed

detection_rules/etc/deprecated_rules.json

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
{
2+
"015cca13-8832-49ac-a01b-a396114809f6": {
3+
"deprecation_date": "2026/01/16",
4+
"rule_name": "Deprecated - AWS Redshift Cluster Creation",
5+
"stack_version": "8.19"
6+
},
27
"03a514d9-500e-443e-b6a9-72718c548f6c": {
38
"deprecation_date": "2025/03/14",
49
"rule_name": "Deprecated - SSH Process Launched From Inside A Container",
@@ -59,6 +64,11 @@
5964
"rule_name": "Linux Restricted Shell Breakout via c89/c99 Shell evasion",
6065
"stack_version": "7.16"
6166
},
67+
"1ba5160d-f5a2-4624-b0ff-6a1dc55d2516": {
68+
"deprecation_date": "2026/01/16",
69+
"rule_name": "Deprecated - AWS ElastiCache Security Group Modified or Deleted",
70+
"stack_version": "8.19"
71+
},
6272
"1c84dd64-7e6c-4bad-ac73-a5014ee37042": {
6373
"deprecation_date": "2025/06/26",
6474
"rule_name": "Deprecated - Suspicious File Creation in /etc for Persistence",
@@ -104,6 +114,11 @@
104114
"rule_name": "Potential Privilege Escalation via Local Kerberos Relay over LDAP",
105115
"stack_version": "7.16"
106116
},
117+
"378f9024-8a0c-46a5-aa08-ce147ac73a4e": {
118+
"deprecation_date": "2026/01/16",
119+
"rule_name": "Deprecated - AWS RDS Security Group Creation",
120+
"stack_version": "8.19"
121+
},
107122
"3a86e085-094c-412d-97ff-2439731e59cb": {
108123
"deprecation_date": "2021/03/03",
109124
"rule_name": "Setgid Bit Set via chmod",
@@ -204,6 +219,11 @@
204219
"rule_name": "File and Directory Discovery",
205220
"stack_version": "7.16"
206221
},
222+
"7b3da11a-60a2-412e-8aa7-011e1eb9ed47": {
223+
"deprecation_date": "2026/01/16",
224+
"rule_name": "Deprecated - AWS ElastiCache Security Group Created",
225+
"stack_version": "8.19"
226+
},
207227
"7d2c38d7-ede7-4bdf-b140-445906e6c540": {
208228
"deprecation_date": "2021/04/15",
209229
"rule_name": "Tor Activity to the Internet",
@@ -219,6 +239,11 @@
219239
"rule_name": "Linux Restricted Shell Breakout via the mysql command",
220240
"stack_version": "7.16"
221241
},
242+
"863cdf31-7fd3-41cf-a185-681237ea277b": {
243+
"deprecation_date": "2026/01/16",
244+
"rule_name": "Deprecated - AWS RDS Security Group Deletion",
245+
"stack_version": "8.19"
246+
},
222247
"86c3157c-a951-4a4f-989b-2f0d0f1f9518": {
223248
"deprecation_date": "2024/02/22",
224249
"rule_name": "Potential Linux Reverse Connection through Port Knocking",
@@ -374,11 +399,21 @@
374399
"rule_name": "Whitespace Padding in Process Command Line",
375400
"stack_version": "7.16"
376401
},
402+
"e14c5fd7-fdd7-49c2-9e5b-ec49d817bc8d": {
403+
"deprecation_date": "2026/01/16",
404+
"rule_name": "Deprecated - AWS RDS Cluster Creation",
405+
"stack_version": "8.19"
406+
},
377407
"e56993d2-759c-4120-984c-9ec9bb940fd5": {
378408
"deprecation_date": "2021/04/15",
379409
"rule_name": "RDP (Remote Desktop Protocol) to the Internet",
380410
"stack_version": "7.14.0"
381411
},
412+
"e919611d-6b6f-493b-8314-7ed6ac2e413b": {
413+
"deprecation_date": "2026/01/16",
414+
"rule_name": "Deprecated - AWS EC2 VM Export Failure",
415+
"stack_version": "8.19"
416+
},
382417
"e9b4a3c7-24fc-49fd-a00f-9c938031eef1": {
383418
"deprecation_date": "2022/05/09",
384419
"rule_name": "Linux Restricted Shell Breakout via busybox Shell Evasion",
@@ -394,11 +429,21 @@
394429
"rule_name": "Suspicious Network Connection Attempt by Root",
395430
"stack_version": "8.3"
396431
},
432+
"ecf2b32c-e221-4bd4-aa3b-c7d59b3bc01d": {
433+
"deprecation_date": "2026/01/16",
434+
"rule_name": "Deprecated - AWS RDS Instance/Cluster Stoppage",
435+
"stack_version": "8.19"
436+
},
397437
"ee619805-54d7-4c56-ba6f-7717282ddd73": {
398438
"deprecation_date": "2022/05/09",
399439
"rule_name": "Linux Restricted Shell Breakout via crash Shell evasion",
400440
"stack_version": "7.16"
401441
},
442+
"f30f3443-4fbb-4c27-ab89-c3ad49d62315": {
443+
"deprecation_date": "2026/01/16",
444+
"rule_name": "Deprecated - AWS RDS Instance Creation",
445+
"stack_version": "8.19"
446+
},
402447
"f52362cd-baf1-4b6d-84be-064efc826461": {
403448
"deprecation_date": "2022/05/09",
404449
"rule_name": "Linux Restricted Shell Breakout via flock Shell evasion",

0 commit comments

Comments
 (0)