Skip to content

Commit

Permalink
[Rule Tuning] 3rd Party EDR - Add Crowdstrike FDR support - 3 (#4222)
Browse files Browse the repository at this point in the history
Removed changes from:
- rules/windows/defense_evasion_masquerading_trusted_directory.toml
- rules/windows/defense_evasion_wsl_child_process.toml
- rules/windows/execution_apt_solarwinds_backdoor_child_cmd_powershell.toml
- rules/windows/execution_enumeration_via_wmiprvse.toml
- rules/windows/execution_initial_access_foxmail_exploit.toml
- rules/windows/execution_suspicious_cmd_wmi.toml
- rules/windows/execution_suspicious_pdf_reader.toml
- rules/windows/execution_via_compiled_html_file.toml
- rules/windows/execution_via_mmc_console_file_unusual_path.toml

(selectively cherry picked from commit 2b6116e)
  • Loading branch information
w0rk3r authored and github-actions[bot] committed Nov 4, 2024
1 parent 01f12f1 commit b586c73
Showing 1 changed file with 4 additions and 3 deletions.
7 changes: 4 additions & 3 deletions rules/windows/execution_mofcomp.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2023/08/23"
integration = ["endpoint", "m365_defender", "system"]
integration = ["endpoint", "m365_defender", "system", "crowdstrike"]
maturity = "production"
updated_date = "2024/10/10"
updated_date = "2024/10/31"

[rule]
author = ["Elastic"]
Expand All @@ -12,7 +12,7 @@ files to build their own namespaces and classes into the Windows Management Inst
establish persistence using WMI Event Subscription.
"""
from = "now-9m"
index = ["logs-endpoint.events.process-*", "logs-m365_defender.event-*", "endgame-*", "logs-system.security-*"]
index = ["logs-endpoint.events.process-*", "logs-m365_defender.event-*", "endgame-*", "logs-system.security-*", "logs-crowdstrike.fdr*"]
language = "eql"
license = "Elastic License v2"
name = "Mofcomp Activity"
Expand All @@ -28,6 +28,7 @@ tags = [
"Data Source: Microsoft Defender for Endpoint",
"Data Source: Elastic Endgame",
"Data Source: System",
"Data Source: Crowdstrike",
]
timestamp_override = "event.ingested"
type = "eql"
Expand Down

0 comments on commit b586c73

Please sign in to comment.