Skip to content

Commit

Permalink
Updated failing rules for integrations checks
Browse files Browse the repository at this point in the history
  • Loading branch information
eric-forte-elastic committed Oct 21, 2024
1 parent 5db426e commit 252e9c6
Show file tree
Hide file tree
Showing 46 changed files with 92 additions and 92 deletions.
4 changes: 2 additions & 2 deletions rules/windows/command_and_control_rdp_tunnel_plink.toml
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
[metadata]
creation_date = "2020/10/14"
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel"]
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "system"]
maturity = "production"
min_stack_comments = "SentinelOne integration package minimum version for validation."
min_stack_version = "8.11.0"
updated_date = "2024/05/16"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
[metadata]
creation_date = "2024/03/27"
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel"]
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "system"]
maturity = "production"
min_stack_comments = "SentinelOne integration package minimum version for validation."
min_stack_version = "8.11.0"
updated_date = "2024/05/16"
updated_date = "2024/10/21"


[rule]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/credential_access_cmdline_dump_tool.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/24"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/03/18"
integration = ["endpoint", "m365_defender"]
integration = ["endpoint", "m365_defender", "windows"]
maturity = "production"
updated_date = "2024/10/10"
updated_date = "2024/10/21"

[transform]
[[transform.osquery]]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2022/04/30"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/credential_access_saved_creds_vaultcmd.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/01/19"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/12/25"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic", "Austin Songer"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/11/27"
integration = ["windows"]
integration = ["windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/07/07"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/08/21"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/07/07"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/03/25"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/03/25"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/defense_evasion_from_unusual_directory.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/10/30"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/10/21"

[transform]
[[transform.osquery]]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/08/24"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/18"
integration = ["endpoint", "windows", "m365_defender"]
integration = ["endpoint", "windows", "m365_defender", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/defense_evasion_sip_provider_mod.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/01/20"
integration = ["endpoint"]
integration = ["endpoint", "windows"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
[metadata]
creation_date = "2020/09/03"
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel"]
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "system"]
maturity = "production"
min_stack_comments = "SentinelOne integration package minimum version for validation."
min_stack_version = "8.11.0"
updated_date = "2024/05/16"
updated_date = "2024/10/21"

[transform]
[[transform.osquery]]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/08/19"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/defense_evasion_via_filter_manager.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/02/18"
integration = ["endpoint", "windows", "m365_defender"]
integration = ["endpoint", "windows", "m365_defender", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[transform]
[[transform.osquery]]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/discovery_group_policy_object_discovery.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2023/01/18"
integration = ["windows", "endpoint"]
integration = ["windows", "endpoint", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/discovery_peripheral_device.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/02"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/execution_com_object_xwizard.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/01/20"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/execution_suspicious_pdf_reader.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/03/30"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/execution_via_compiled_html_file.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/02/18"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[transform]
[[transform.osquery]]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
[metadata]
creation_date = "2024/06/19"
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender"]
integration = ["endpoint", "windows", "sentinel_one_cloud_funnel", "m365_defender", "system"]
maturity = "production"
min_stack_comments = "Breaking change at 8.8.0 for Sentinel One Cloud Funnel Integration"
min_stack_version = "8.12.0"
updated_date = "2024/07/09"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
4 changes: 2 additions & 2 deletions rules/windows/impact_modification_of_boot_config.toml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/03/16"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/02/18"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2024/03/26"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2021/03/22"
integration = ["endpoint"]
integration = ["endpoint", "windows"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/11"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/02"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/04"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/07/16"
integration = ["endpoint", "windows"]
integration = ["endpoint", "windows", "system"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
[metadata]
creation_date = "2020/11/17"
integration = ["endpoint"]
integration = ["endpoint", "windows"]
maturity = "production"
updated_date = "2024/08/07"
updated_date = "2024/10/21"

[rule]
author = ["Elastic"]
Expand Down
Loading

0 comments on commit 252e9c6

Please sign in to comment.