@@ -5,6 +5,101 @@ The following lists prebuilt rule updates per release. Only rules with
5
5
significant modifications to their query or scope are listed. For detailed
6
6
information about a rule's changes, see the rule's description page.
7
7
8
+ [float]
9
+ === 8.6.0
10
+
11
+ <<a-scheduled-task-was-created>>
12
+
13
+ <<a-scheduled-task-was-updated>>
14
+
15
+ <<abnormal-process-id-or-lock-file-created>>
16
+
17
+ <<accepted-default-telnet-port-connection>>
18
+
19
+ <<account-password-reset-remotely>>
20
+
21
+ <<adversary-behavior-detected-elastic-endgame>>
22
+
23
+ <<clearing-windows-console-history>>
24
+
25
+ <<component-object-model-hijacking>>
26
+
27
+ <<connection-to-commonly-abused-web-services>>
28
+
29
+ <<creation-or-modification-of-root-certificate>>
30
+
31
+ <<file-transfer-or-listener-established-via-netcat>>
32
+
33
+ <<kubernetes-anonymous-request-authorized>>
34
+
35
+ <<kubernetes-exposed-service-created-with-type-nodeport>>
36
+
37
+ <<kubernetes-pod-created-with-hostipc>>
38
+
39
+ <<kubernetes-pod-created-with-hostnetwork>>
40
+
41
+ <<kubernetes-pod-created-with-hostpid>>
42
+
43
+ <<kubernetes-pod-created-with-a-sensitive-hostpath-volume>>
44
+
45
+ <<kubernetes-privileged-pod-created>>
46
+
47
+ <<kubernetes-suspicious-assignment-of-controller-service-account>>
48
+
49
+ <<kubernetes-suspicious-self-subject-review>>
50
+
51
+ <<kubernetes-user-exec-into-pod>>
52
+
53
+ <<ms-office-macro-security-registry-modifications>>
54
+
55
+ <<modification-of-amsienable-registry-key>>
56
+
57
+ <<modification-of-wdigest-security-provider>>
58
+
59
+ <<network-logon-provider-registry-modification>>
60
+
61
+ <<nullsessionpipe-registry-modification>>
62
+
63
+ <<port-forwarding-rule-addition>>
64
+
65
+ <<potential-application-shimming-via-sdbinst>>
66
+
67
+ <<potential-process-herpaderping-attempt>>
68
+
69
+ <<potential-remote-credential-access-via-registry>>
70
+
71
+ <<potential-shadow-credentials-added-to-ad-object>>
72
+
73
+ <<potential-shadow-file-read-via-command-line-utilities>>
74
+
75
+ <<powershell-script-block-logging-disabled>>
76
+
77
+ <<process-creation-via-secondary-logon>>
78
+
79
+ <<process-termination-followed-by-deletion>>
80
+
81
+ <<remote-computer-account-dnshostname-update>>
82
+
83
+ <<sip-provider-modification>>
84
+
85
+ <<scheduled-tasks-at-command-enabled>>
86
+
87
+ <<solarwinds-process-disabling-services-via-registry>>
88
+
89
+ <<suspicious-file-creation-in-etc-for-persistence>>
90
+
91
+ <<suspicious-powershell-engine-imageload>>
92
+
93
+ <<suspicious-wmi-image-load-from-ms-office>>
94
+
95
+ <<system-log-file-deletion>>
96
+
97
+ <<temporarily-scheduled-task-creation>>
98
+
99
+ <<windows-defender-disabled-via-registry-modification>>
100
+
101
+ <<windows-registry-file-creation-in-smb-share>>
102
+
8
103
[float]
9
104
=== 8.5.0
10
105
@@ -409,8 +504,6 @@ information about a rule's changes, see the rule's description page.
409
504
410
505
<<gcp-iam-service-account-key-deletion>>
411
506
412
- <<gcp-kubernetes-rolebindings-created-or-patched>>
413
-
414
507
<<gcp-logging-bucket-deletion>>
415
508
416
509
<<gcp-logging-sink-deletion>>
@@ -730,8 +823,6 @@ information about a rule's changes, see the rule's description page.
730
823
731
824
<<disabling-user-account-control-via-registry-modification>>
732
825
733
- <<gcp-kubernetes-rolebindings-created-or-patched>>
734
-
735
826
<<installation-of-security-support-provider>>
736
827
737
828
<<kerberos-traffic-from-unusual-process>>
@@ -930,6 +1021,8 @@ information about a rule's changes, see the rule's description page.
930
1021
[float]
931
1022
=== 7.14.0
932
1023
1024
+ <<accepted-default-telnet-port-connection>>
1025
+
933
1026
<<apple-script-execution-followed-by-network-connection>>
934
1027
935
1028
<<attempts-to-brute-force-a-microsoft-365-user-account>>
@@ -1014,8 +1107,6 @@ information about a rule's changes, see the rule's description page.
1014
1107
1015
1108
<<suspicious-powershell-engine-imageload>>
1016
1109
1017
- <<telnet-port-activity>>
1018
-
1019
1110
<<unusual-network-connection-via-rundll32>>
1020
1111
1021
1112
<<vnc-virtual-network-computing-from-the-internet>>
@@ -1237,7 +1328,7 @@ information about a rule's changes, see the rule's description page.
1237
1328
1238
1329
<<user-account-creation>>
1239
1330
1240
- <<user-added-to-privileged-group-in-active-directory >>
1331
+ <<user-added-to-privileged-group>>
1241
1332
1242
1333
<<volume-shadow-copy-deleted-or-resized-via-vssadmin>>
1243
1334
@@ -1564,14 +1655,14 @@ information about a rule's changes, see the rule's description page.
1564
1655
1565
1656
<<direct-outbound-smb-connection>>
1566
1657
1658
+ <<file-transfer-or-listener-established-via-netcat>>
1659
+
1567
1660
<<microsoft-build-engine-using-an-alternate-name>>
1568
1661
1569
1662
<<modification-or-removal-of-an-okta-application-sign-on-policy>>
1570
1663
1571
1664
<<msbuild-making-network-connections>>
1572
1665
1573
- <<netcat-network-activity>>
1574
-
1575
1666
<<network-connection-via-certutil>>
1576
1667
1577
1668
<<network-connection-via-compiled-html-file>>
@@ -1611,6 +1702,8 @@ information about a rule's changes, see the rule's description page.
1611
1702
[float]
1612
1703
=== 7.9.0
1613
1704
1705
+ <<accepted-default-telnet-port-connection>>
1706
+
1614
1707
<<account-discovery-command-via-system-account>>
1615
1708
1616
1709
<<adding-hidden-file-attribute-via-attrib>>
@@ -1645,6 +1738,8 @@ information about a rule's changes, see the rule's description page.
1645
1738
1646
1739
<<file-permission-modification-in-writable-directory>>
1647
1740
1741
+ <<file-transfer-or-listener-established-via-netcat>>
1742
+
1648
1743
<<hping-process-activity>>
1649
1744
1650
1745
<<ipsec-nat-traversal-port-activity>>
@@ -1671,8 +1766,6 @@ information about a rule's changes, see the rule's description page.
1671
1766
1672
1767
<<msbuild-making-network-connections>>
1673
1768
1674
- <<netcat-network-activity>>
1675
-
1676
1769
<<network-connection-via-certutil>>
1677
1770
1678
1771
<<network-connection-via-compiled-html-file>>
@@ -1723,8 +1816,6 @@ information about a rule's changes, see the rule's description page.
1723
1816
1724
1817
<<system-shells-via-services>>
1725
1818
1726
- <<telnet-port-activity>>
1727
-
1728
1819
<<unusual-network-connection-via-rundll32>>
1729
1820
1730
1821
<<unusual-parent-child-relationship>>
@@ -1792,6 +1883,8 @@ These prebuilt rules have been updated:
1792
1883
1793
1884
<<exploit-prevented-elastic-endgame>>
1794
1885
1886
+ <<file-transfer-or-listener-established-via-netcat>>
1887
+
1795
1888
<<hping-process-activity>>
1796
1889
1797
1890
<<local-scheduled-task-creation>>
@@ -1802,8 +1895,6 @@ These prebuilt rules have been updated:
1802
1895
1803
1896
<<msbuild-making-network-connections>>
1804
1897
1805
- <<netcat-network-activity>>
1806
-
1807
1898
<<network-connection-via-compiled-html-file>>
1808
1899
1809
1900
<<network-connection-via-registration-utility>>
@@ -1874,6 +1965,8 @@ These prebuilt rules have been updated:
1874
1965
[float]
1875
1966
=== 7.6.1
1876
1967
1968
+ <<accepted-default-telnet-port-connection>>
1969
+
1877
1970
<<ipsec-nat-traversal-port-activity>>
1878
1971
1879
1972
<<potential-shell-via-web-server>>
@@ -1888,8 +1981,6 @@ These prebuilt rules have been updated:
1888
1981
1889
1982
<<smtp-on-port-26-tcp>>
1890
1983
1891
- <<telnet-port-activity>>
1892
-
1893
1984
<<vnc-virtual-network-computing-from-the-internet>>
1894
1985
1895
1986
<<vnc-virtual-network-computing-to-the-internet>>
0 commit comments