Skip to content

Commit 92fe46b

Browse files
Fix Minstack version for windows integration (#4214)
1 parent 9e4fce6 commit 92fe46b

File tree

58 files changed

+174
-76
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

58 files changed

+174
-76
lines changed

rules/cross-platform/credential_access_cookies_chromium_browsers_debugging.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
[metadata]
22
creation_date = "2020/12/21"
33
integration = ["endpoint", "windows"]
4+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
5+
min_stack_version = "8.14.0"
46
maturity = "production"
5-
updated_date = "2024/05/21"
7+
updated_date = "2024/05/28"
68

79
[rule]
810
author = ["Elastic"]

rules/ml/persistence_ml_windows_anomalous_process_creation.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,10 @@
11
[metadata]
22
creation_date = "2020/03/25"
33
integration = ["endpoint", "windows"]
4+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
5+
min_stack_version = "8.14.0"
46
maturity = "production"
5-
updated_date = "2024/06/18"
7+
updated_date = "2024/10/28"
68

79
[transform]
810
[[transform.osquery]]

rules/windows/collection_mailbox_export_winlog.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2023/01/11"
33
integration = ["windows"]
44
maturity = "production"
5-
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
6-
min_stack_version = "8.12.0"
7-
updated_date = "2024/03/12"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/28"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/collection_posh_audio_capture.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2021/10/19"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/collection_posh_clipboard_capture.toml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,9 @@
22
creation_date = "2023/01/12"
33
integration = ["windows"]
44
maturity = "production"
5-
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
6-
min_stack_version = "8.12.0"
7-
updated_date = "2024/03/12"
5+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
6+
min_stack_version = "8.14.0"
7+
updated_date = "2024/10/28"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/collection_posh_keylogger.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2021/10/15"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/07/17"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/collection_posh_mailbox.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/01/11"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/collection_posh_screen_grabber.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2021/10/19"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/collection_posh_webcam_video_capture.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/07/18"
33
integration = ["windows"]
44
maturity = "production"
5-
updated_date = "2024/05/21"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

rules/windows/command_and_control_new_terms_commonly_abused_rat_execution.toml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
creation_date = "2023/04/03"
33
integration = ["endpoint", "windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/09/23"
5+
updated_date = "2024/10/28"
6+
min_stack_version = "8.14.0"
7+
min_stack_comments = "Breaking change at 8.14.0 for the Windows Integration."
68

79
[rule]
810
author = ["Elastic"]

0 commit comments

Comments
 (0)