Skip to content

Commit

Permalink
Lock versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12 (
Browse files Browse the repository at this point in the history
elastic#3358)

* Locked versions for releases: 8.3,8.4,8.5,8.6,8.7,8.8,8.9,8.10,8.11,8.12

* Update detection_rules/etc/deprecated_rules.json

---------

Co-authored-by: terrancedejesus <[email protected]>
Co-authored-by: Terrance DeJesus <[email protected]>
  • Loading branch information
3 people authored Jan 2, 2024
1 parent 5a96f4d commit f37d13f
Show file tree
Hide file tree
Showing 2 changed files with 168 additions and 146 deletions.
15 changes: 15 additions & 0 deletions detection_rules/etc/deprecated_rules.json
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,11 @@
"rule_name": "GCP Kubernetes Rolebindings Created or Patched",
"stack_version": "8.3"
},
"301571f3-b316-4969-8dd0-7917410030d3": {
"deprecation_date": "2023/12/14",
"rule_name": "Malicious Remote File Creation",
"stack_version": "8.9"
},
"3605a013-6f0c-4f7d-88a5-326f5be262ec": {
"deprecation_date": "2022/08/01",
"rule_name": "Potential Privilege Escalation via Local Kerberos Relay over LDAP",
Expand All @@ -99,6 +104,11 @@
"rule_name": "Deprecated - Potential Process Injection via LD_PRELOAD Environment Variable",
"stack_version": "8.6"
},
"4b1a807a-4e7b-414e-8cea-24bf580f6fc5": {
"deprecation_date": "2023/11/02",
"rule_name": "Deprecated - Potential Reverse Shell via Suspicious Parent Process",
"stack_version": "8.3"
},
"5e87f165-45c2-4b80-bfa5-52822552c997": {
"deprecation_date": "2022/03/16",
"rule_name": "Potential PrintNightmare File Modification",
Expand Down Expand Up @@ -259,6 +269,11 @@
"rule_name": "Process Discovery via Tasklist",
"stack_version": "7.14.0"
},
"ccc55af4-9882-4c67-87b4-449a7ae8079c": {
"deprecation_date": "2023/12/15",
"rule_name": "Potential Process Herpaderping Attempt",
"stack_version": "8.3"
},
"cd4d5754-07e1-41d4-b9a5-ef4ea6a0a126": {
"deprecation_date": "2021/04/15",
"rule_name": "Socat Process Activity",
Expand Down
Loading

0 comments on commit f37d13f

Please sign in to comment.