Skip to content

Commit e6932e8

Browse files
Merge branch 'main' into deprecatemac
2 parents 8bf1066 + 3b1f780 commit e6932e8

File tree

43 files changed

+5129
-2638
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

43 files changed

+5129
-2638
lines changed

detection_rules/etc/deprecated_rules.json

Lines changed: 90 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,9 @@
11
{
2+
"03a514d9-500e-443e-b6a9-72718c548f6c": {
3+
"deprecation_date": "2025/03/14",
4+
"rule_name": "Deprecated - SSH Process Launched From Inside A Container",
5+
"stack_version": "8.14"
6+
},
27
"041d4d41-9589-43e2-ba13-5680af75ebc2": {
38
"deprecation_date": "2023/09/25",
49
"rule_name": "Deprecated - Potential DNS Tunneling via Iodine",
@@ -49,11 +54,21 @@
4954
"rule_name": "SQL Traffic to the Internet",
5055
"stack_version": "7.14.0"
5156
},
57+
"160896de-b66f-42cb-8fef-20f53a9006ea": {
58+
"deprecation_date": "2025/03/14",
59+
"rule_name": "Deprecated - Potential Container Escape via Modified release_agent File",
60+
"stack_version": "8.14"
61+
},
5262
"1859ce38-6a50-422b-a5e8-636e231ea0cd": {
5363
"deprecation_date": "2022/05/09",
5464
"rule_name": "Linux Restricted Shell Breakout via c89/c99 Shell evasion",
5565
"stack_version": "7.16"
5666
},
67+
"1a289854-5b78-49fe-9440-8a8096b1ab50": {
68+
"deprecation_date": "2025/03/14",
69+
"rule_name": "Deprecated - Suspicious Network Tool Launched Inside A Container",
70+
"stack_version": "8.14"
71+
},
5772
"20dc4620-3b68-4269-8124-ca5091e00ea8": {
5873
"deprecation_date": "2022/07/25",
5974
"rule_name": "Auditd Max Login Sessions",
@@ -89,6 +104,11 @@
89104
"rule_name": "Malicious Remote File Creation",
90105
"stack_version": "8.9"
91106
},
107+
"342f834b-21a6-41bf-878c-87d116eba3ee": {
108+
"deprecation_date": "2025/03/14",
109+
"rule_name": "Deprecated - Modification of Dynamic Linker Preload Shared Object Inside A Container",
110+
"stack_version": "8.14"
111+
},
92112
"3605a013-6f0c-4f7d-88a5-326f5be262ec": {
93113
"deprecation_date": "2022/08/01",
94114
"rule_name": "Potential Privilege Escalation via Local Kerberos Relay over LDAP",
@@ -104,11 +124,26 @@
104124
"rule_name": "Deprecated - Potential Password Spraying of Microsoft 365 User Accounts",
105125
"stack_version": "8.12"
106126
},
127+
"41f7da9e-4e9f-4a81-9b58-40d725d83bc0": {
128+
"deprecation_date": "2025/03/14",
129+
"rule_name": "Deprecated - Mount Launched Inside a Privileged Container",
130+
"stack_version": "8.14"
131+
},
132+
"420e5bb4-93bf-40a3-8f4a-4cc1af90eca1": {
133+
"deprecation_date": "2025/03/14",
134+
"rule_name": "Deprecated - Interactive Exec Command Launched Against A Running Container",
135+
"stack_version": "8.14"
136+
},
107137
"43303fd4-4839-4e48-b2b2-803ab060758d": {
108138
"deprecation_date": "2022/09/13",
109139
"rule_name": "Web Application Suspicious Activity: No User Agent",
110140
"stack_version": "8.5"
111141
},
142+
"475b42f0-61fb-4ef0-8a85-597458bfb0a1": {
143+
"deprecation_date": "2025/03/14",
144+
"rule_name": "Deprecated - Sensitive Files Compression Inside A Container",
145+
"stack_version": "8.14"
146+
},
112147
"47f09343-8d1f-4bb5-8bb0-00c9d18f5010": {
113148
"deprecation_date": "2021/03/17",
114149
"rule_name": "Execution via Regsvcs/Regasm",
@@ -129,6 +164,11 @@
129164
"rule_name": "Deprecated - Potential Reverse Shell via Suspicious Parent Process",
130165
"stack_version": "8.3"
131166
},
167+
"4b4e9c99-27ea-4621-95c8-82341bc6e512": {
168+
"deprecation_date": "2025/03/14",
169+
"rule_name": "Deprecated - Container Workload Protection",
170+
"stack_version": "8.14"
171+
},
132172
"5e87f165-45c2-4b80-bfa5-52822552c997": {
133173
"deprecation_date": "2022/03/16",
134174
"rule_name": "Potential PrintNightmare File Modification",
@@ -159,6 +199,11 @@
159199
"rule_name": "Deprecated - Threat Intel Filebeat Module (v8.x) Indicator Match",
160200
"stack_version": "8.5"
161201
},
202+
"6c6bb7ea-0636-44ca-b541-201478ef6b50": {
203+
"deprecation_date": "2025/03/14",
204+
"rule_name": "Deprecated - Container Management Utility Run Inside A Container",
205+
"stack_version": "8.14"
206+
},
162207
"6ea71ff0-9e95-475b-9506-2580d1ce6154": {
163208
"deprecation_date": "2022/08/02",
164209
"rule_name": "DNS Activity to the Internet",
@@ -224,6 +269,11 @@
224269
"rule_name": "Deprecated - Suspicious JAVA Child Process",
225270
"stack_version": "8.12"
226271
},
272+
"8d3d0794-c776-476b-8674-ee2e685f6470": {
273+
"deprecation_date": "2025/03/14",
274+
"rule_name": "Deprecated - Suspicious Interactive Shell Spawned From Inside A Container",
275+
"stack_version": "8.14"
276+
},
227277
"8fed8450-847e-43bd-874c-3bbf0cd425f3": {
228278
"deprecation_date": "2022/05/09",
229279
"rule_name": "Linux Restricted Shell Breakout via apt/apt-get Changelog Escape",
@@ -234,6 +284,16 @@
234284
"rule_name": "Auditd Login Attempt at Forbidden Time",
235285
"stack_version": "7.16"
236286
},
287+
"9661ed8b-001c-40dc-a777-0983b7b0c91a": {
288+
"deprecation_date": "2025/03/14",
289+
"rule_name": "Deprecated - Sensitive Keys Or Passwords Searched For Inside A Container",
290+
"stack_version": "8.14"
291+
},
292+
"97697a52-4a76-4f0a-aa4f-25c178aae6eb": {
293+
"deprecation_date": "2025/03/14",
294+
"rule_name": "Deprecated - File System Debugger Launched Inside a Privileged Container",
295+
"stack_version": "8.14"
296+
},
237297
"97da359b-2b61-4a40-b2e4-8fc48cf7a294": {
238298
"deprecation_date": "2022/05/09",
239299
"rule_name": "Linux Restricted Shell Breakout via the SSH command",
@@ -259,6 +319,11 @@
259319
"rule_name": "Network Connection via Mshta",
260320
"stack_version": "7.10.0"
261321
},
322+
"a52a9439-d52c-401c-be37-2785235c6547": {
323+
"deprecation_date": "2025/03/14",
324+
"rule_name": "Deprecated - Netcat Listener Established Inside A Container",
325+
"stack_version": "8.14"
326+
},
262327
"a5f0d057-d540-44f5-924d-c6a2ae92f045": {
263328
"deprecation_date": "2023/06/22",
264329
"rule_name": "Potential SSH Brute Force Detected on Privileged Account",
@@ -309,6 +374,11 @@
309374
"rule_name": "Socat Process Activity",
310375
"stack_version": "7.14.0"
311376
},
377+
"d0b0f3ed-0b37-44bf-adee-e8cb7de92767": {
378+
"deprecation_date": "2025/03/14",
379+
"rule_name": "Deprecated - AWS Credentials Searched For Inside A Container",
380+
"stack_version": "8.14"
381+
},
312382
"d2053495-8fe7-4168-b3df-dad844046be3": {
313383
"deprecation_date": "2021/04/15",
314384
"rule_name": "PPTP (Point to Point Tunneling Protocol) Activity",
@@ -364,16 +434,36 @@
364434
"rule_name": "Suspicious Network Connection Attempt by Root",
365435
"stack_version": "8.3"
366436
},
437+
"ec604672-bed9-43e1-8871-cf591c052550": {
438+
"deprecation_date": "2025/03/14",
439+
"rule_name": "Deprecated - File Made Executable via Chmod Inside A Container",
440+
"stack_version": "8.14"
441+
},
367442
"ee619805-54d7-4c56-ba6f-7717282ddd73": {
368443
"deprecation_date": "2022/05/09",
369444
"rule_name": "Linux Restricted Shell Breakout via crash Shell evasion",
370445
"stack_version": "7.16"
371446
},
447+
"ef65e82c-d8b4-4895-9824-5f6bc6166804": {
448+
"deprecation_date": "2025/03/14",
449+
"rule_name": "Deprecated - Potential Container Escape via Modified notify_on_release File",
450+
"stack_version": "8.14"
451+
},
372452
"f52362cd-baf1-4b6d-84be-064efc826461": {
373453
"deprecation_date": "2022/05/09",
374454
"rule_name": "Linux Restricted Shell Breakout via flock Shell evasion",
375455
"stack_version": "7.16"
376456
},
457+
"f5488ac1-099e-4008-a6cb-fb638a0f0828": {
458+
"deprecation_date": "2025/03/14",
459+
"rule_name": "Deprecated - SSH Connection Established Inside A Running Container",
460+
"stack_version": "8.14"
461+
},
462+
"f7769104-e8f9-4931-94a2-68fc04eadec3": {
463+
"deprecation_date": "2025/03/14",
464+
"rule_name": "Deprecated - SSH Authorized Keys File Modified Inside a Container",
465+
"stack_version": "8.14"
466+
},
377467
"fb9937ce-7e21-46bf-831d-1ad96eac674d": {
378468
"deprecation_date": "2022/07/25",
379469
"rule_name": "Auditd Max Failed Login Attempts",

0 commit comments

Comments
 (0)