Skip to content

Tags: aminemirat/detection-rules

Tags

v7.11.0

Toggle v7.11.0's commit message
Add v7.11.0 tag

ML-experimental-detections-20201221-2

Toggle ML-experimental-detections-20201221-2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
update incomplete bug fix from 736 for 7.11 -> 7.10 downgrade logic

ML-DGA-20201216-1

Toggle ML-DGA-20201216-1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
strip trailing slash in kibana_url only when defined

ML-experimental-detections-20201209-1

Toggle ML-experimental-detections-20201209-1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature. The key has expired.
[New Rule] High Number of Process and/or Services Termination (elasti…

…c#672)

* [New Rule] High Number of Process and/or Services Termination

* removed url and fixed ruleid

* fixed tags

* Update rules/windows/defense_evasion_stop_process_service_threshold.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>

* Update rules/windows/defense_evasion_stop_process_service_threshold.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* relinted

* Update rules/windows/defense_evasion_stop_process_service_threshold.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

* Update rules/windows/defense_evasion_stop_process_service_threshold.toml

Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>

v7.10.0

Toggle v7.10.0's commit message
Add v7.10.0 tag

v7.9.1

Toggle v7.9.1's commit message
Add v7.9.1 tag

v7.9.0

Toggle v7.9.0's commit message
Add v7.9.0 tag