You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"Cobalt Strike Command and Control Beacon" SIEM rule uses Lucene query with lowercase operators. The result is that it alerts on all kinds of events containing 'or' and 'and'..
Query:
((event.category: (network or network_traffic) and type: (tls or http)) or event.dataset: (network_traffic.tls or network_traffic.http)) and destination.domain:/[a-z]{3}.stage.[0-9]{8}\..*/
Screenshots
If applicable, add screenshots to help explain your problem.
Version: 8.10.2
The text was updated successfully, but these errors were encountered:
Hey @willemdh, just fixed this one and a few other Lucene queries in this PR: #3196, let me know if there is anything else to fix, thanks for the contribution!
"Cobalt Strike Command and Control Beacon" SIEM rule uses Lucene query with lowercase operators. The result is that it alerts on all kinds of events containing 'or' and 'and'..
Query:
((event.category: (network or network_traffic) and type: (tls or http)) or event.dataset: (network_traffic.tls or network_traffic.http)) and destination.domain:/[a-z]{3}.stage.[0-9]{8}\..*/
Screenshots
If applicable, add screenshots to help explain your problem.
The text was updated successfully, but these errors were encountered: