-
Notifications
You must be signed in to change notification settings - Fork 511
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[New Rule] Endpoint Security Promotion Rules for Specific Events #3533
Conversation
rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml
Show resolved
Hide resolved
…astic/detection-rules into new-rule-endpoint-security-promotions
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
other than severity that need to be bumped, rest looks fine
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml
Outdated
Show resolved
Hide resolved
@terrancedejesus re: testing we need to coordinate with @banderror and the RM team to double check on what they expect from the rules side. Moving to blocked in the interim. |
…revented.toml Co-authored-by: Terrance DeJesus <[email protected]>
….toml Co-authored-by: Terrance DeJesus <[email protected]>
….toml Co-authored-by: Terrance DeJesus <[email protected]>
….toml Co-authored-by: Terrance DeJesus <[email protected]>
…d.toml Co-authored-by: Terrance DeJesus <[email protected]>
…d.toml Co-authored-by: Terrance DeJesus <[email protected]>
…eat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]>
…d.toml Co-authored-by: Terrance DeJesus <[email protected]>
…eat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]>
…eat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]>
…eat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]>
…etected.toml Co-authored-by: Terrance DeJesus <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The new rules should not be enabled out of the box. + added Natasha's change in the relevant places. The rest looks good to me! Thanks!
rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/impact_elastic_ransomware_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/impact_elastic_ransomware_detected.toml
Outdated
Show resolved
Hide resolved
rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml
Outdated
Show resolved
Hide resolved
…b.com/elastic/detection-rules into new-rule-endpoint-security-promotions
@approksiu thanks for the review, suggested changes applied ( QQ - why don't make those new promotion rules by default enabled and switch the existing one to false ? (maybe users won't notice those new promotion rules and don't get the benefit of this change) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks team! Looks good!
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
* new endpoint security rules for specific alerts * updated risk scores * fixed rule names and UUIDs * changed logic to use message field for detection vs prevention * reverting changes * reverting changes * reverting to old commit * reverting to old commit * reverting to old commit * reverting to old commit * changed naming to Elastic Defend * updated rule dates and min-stacks * linted; adjusted queries * updated ransomware, memory sig or shellcode risk * Update rules/integrations/endpoint/elastic_endpoint_security.toml * updated promotion rule * fixed typos in naming * updated setup guides * added intervals * added MITRE * added investigation guide for Memory Threat * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: natasha-moore-elastic <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_detected.toml Co-authored-by: Samirbous <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_ransomware_prevented.toml Co-authored-by: Samirbous <[email protected]> * ++ * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml * Update rules/integrations/endpoint/elastic_endpoint_security_malicious_file_detected.toml * Update rules/integrations/endpoint/elastic_endpoint_security_memory_signature_prevented.toml * ++ * ++ * ++ * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/elastic_endpoint_security_behavior_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/execution_elastic_malicious_file_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update rules/integrations/endpoint/defense_evasion_elastic_memory_threat_prevented.toml Co-authored-by: Terrance DeJesus <[email protected]> * Update defense_evasion_elastic_memory_threat_prevented.toml * toml-lint * Update rules/integrations/endpoint/execution_elastic_malicious_file_detected.toml Co-authored-by: Terrance DeJesus <[email protected]> * ++ --------- Co-authored-by: Mika Ayenson <[email protected]> Co-authored-by: Samirbous <[email protected]> Co-authored-by: natasha-moore-elastic <[email protected]> Co-authored-by: Samirbous <[email protected]> (cherry picked from commit 9fb2dea)
Issues
Summary
This pull request includes 8 new promotional rules. These promotional rules are for the Elastic Defend integration, more specifically, the Endpoint Security feature and alerts.
Before this pull request, we had a single promotional rule that captured all Elastic Endpoint Security alerts.
Additional notes:
event.code
was used to distinguish between each Defend policy featureResponses.message
was used to distinguish between prevention and detection. TheResponses.
fields are only available in alert docs if prevention measures were taken or assigned to the rule or feature.shellcode_thread
is not a specific feature in the Defend policy, it was added to thememory_signature
alerts.Please refer to the issue linked for further information or to continue conversation and considerations for these changes.
Testing Evidence
TBD