Skip to content

Commit 7c92112

Browse files
Fix Minstack version for windows integration - Pahse 2
1 parent 92fe46b commit 7c92112

File tree

52 files changed

+156
-58
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

52 files changed

+156
-58
lines changed

rules/cross-platform/defense_evasion_deleting_websvr_access_logs.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/11/03"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/cross-platform/impact_hosts_file_modified.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/07/07"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_host.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/09/19"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_parent_process.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/problemchild/defense_evasion_ml_rare_process_for_a_user.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_event_high_probability.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/08/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_host.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_parent_process.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/integrations/problemchild/defense_evasion_ml_suspicious_windows_process_cluster_from_user.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/10/16"
33
integration = ["problemchild", "endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 75

rules/ml/credential_access_ml_windows_anomalous_metadata_process.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2020/09/22"
33
integration = ["endpoint", "windows"]
44
maturity = "production"
5-
updated_date = "2024/06/18"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
anomaly_threshold = 50

0 commit comments

Comments
 (0)