Skip to content

Commit b7fc26a

Browse files
Updated failing rules for integrations check
1 parent 7a6889a commit b7fc26a

23 files changed

+46
-46
lines changed

rules/windows/command_and_control_rdp_tunnel_plink.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2020/10/14"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender", "system"]
44
maturity = "production"
55
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
66
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
7+
updated_date = "2024/10/21"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_screenconnect_childproc.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2024/03/27"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender", "system"]
44
maturity = "production"
55
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
66
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
7+
updated_date = "2024/10/21"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/command_and_control_tunnel_vscode.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2024/09/09"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender", "system"]
44
maturity = "production"
55
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
66
min_stack_version = "8.13.0"
7-
updated_date = "2024/09/25"
7+
updated_date = "2024/10/21"
88

99
[rule]
1010
author = ["Elastic"]

rules/windows/credential_access_cmdline_dump_tool.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2020/11/24"
3-
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel", "system"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66
min_stack_version = "8.13.0"
77
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
88

rules/windows/credential_access_persistence_network_logon_provider_modification.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/03/18"
3-
integration = ["endpoint", "m365_defender"]
3+
integration = ["endpoint", "m365_defender", "windows"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66

77
[transform]
88
[[transform.osquery]]

rules/windows/credential_access_saved_creds_vaultcmd.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/01/19"
3-
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel", "system"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66
min_stack_version = "8.13.0"
77
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
88

rules/windows/credential_access_via_snapshot_lsass_clone_creation.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/11/27"
3-
integration = ["windows"]
3+
integration = ["windows", "system"]
44
maturity = "production"
5-
updated_date = "2024/08/07"
5+
updated_date = "2024/10/21"
66

77
[rule]
88
author = ["Elastic"]

rules/windows/defense_evasion_from_unusual_directory.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2020/10/30"
3-
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "windows", "m365_defender", "sentinel_one_cloud_funnel", "system"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66
min_stack_version = "8.13.0"
77
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
88

rules/windows/defense_evasion_sip_provider_mod.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
[metadata]
22
creation_date = "2021/01/20"
3-
integration = ["endpoint", "m365_defender", "sentinel_one_cloud_funnel"]
3+
integration = ["endpoint", "m365_defender", "sentinel_one_cloud_funnel", "windows"]
44
maturity = "production"
5-
updated_date = "2024/10/10"
5+
updated_date = "2024/10/21"
66
min_stack_version = "8.13.0"
77
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
88

rules/windows/defense_evasion_suspicious_zoom_child_process.toml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,10 @@
11
[metadata]
22
creation_date = "2020/09/03"
3-
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
3+
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender", "system"]
44
maturity = "production"
55
min_stack_comments = "Breaking change at 8.13.0 for SentinelOne Integration."
66
min_stack_version = "8.13.0"
7-
updated_date = "2024/08/07"
7+
updated_date = "2024/10/21"
88

99
[transform]
1010
[[transform.osquery]]

0 commit comments

Comments
 (0)