Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ afterEvents:
- field: log.hostId
operator: filter_term
value: '{{.log.hostId}}'
within: now-30m
within: 30m
count: 10
groupBy:
- lastEvent.log.eventType
Expand Down
2 changes: 1 addition & 1 deletion rules/antivirus/bitdefender_gz/av_policy_override.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: log.hostId
operator: filter_term
value: '{{.log.hostId}}'
within: now-1h
within: 1h
count: 3
groupBy:
- lastEvent.log.eventType
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ afterEvents:
- field: log.eventType
operator: filter_term
value: "AntiMalware"
within: now-2h
within: 2h
count: 10
groupBy:
- lastEvent.log.signatureID
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@ afterEvents:
- field: log.eventType
operator: filter_term
value: "AntiMalware"
within: now-1h
within: 1h
count: 5
groupBy:
- lastEvent.log.hostId
Expand Down
4 changes: 2 additions & 2 deletions rules/antivirus/bitdefender_gz/network_threat_detection.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ afterEvents:
- field: origin.ip
operator: filter_term
value: '{{.origin.ip}}'
within: now-2h
within: 2h
count: 5
or:
- indexPattern: v11-log-antivirus-bitdefender-gz-*
Expand All @@ -50,7 +50,7 @@ afterEvents:
- field: log.eventType
operator: filter_term
value: 'network-sandboxing'
within: now-4h
within: 4h
count: 3
groupBy:
- lastEvent.log.hostId
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ afterEvents:
- field: log.hostId
operator: filter_term
value: '{{.log.hostId}}'
within: now-10m
within: 10m
count: 5
groupBy:
- lastEvent.log.hostId
Expand Down
2 changes: 1 addition & 1 deletion rules/antivirus/bitdefender_gz/usb_malware_propagation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: log.hostId
operator: filter_term
value: '{{.log.hostId}}'
within: now-30m
within: 30m
count: 5
groupBy:
- lastEvent.log.eventType
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ afterEvents:
- field: log.tacticName
operator: filter_term
value: '{{.log.tacticName}}'
within: now-15m
within: 15m
count: 3
groupBy:
- lastEvent.log.tacticName
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.event_type
operator: filter_term
value: 'decoy_accessed'
within: now-2h
within: 2h
count: 3
groupBy:
- lastEvent.log.decoy_file
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ afterEvents:
- field: log.eventType
operator: filter_term
value: 'token_access'
within: now-1h
within: 1h
count: 3
groupBy:
- lastEvent.log.tokenId
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ afterEvents:
- field: log.resourceType
operator: filter_term
value: 'network_share'
within: now-30m
within: 30m
count: 3
deduplicateBy:
- adversary.ip
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: log.eventType
operator: filter_term
value: decoy_access
within: now-1h
within: 1h
count: 5
groupBy:
- lastEvent.log.tableName
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ afterEvents:
- field: log.source_ip
operator: filter_term
value: '{{.log.source_ip}}'
within: now-15m
within: 15m
count: 10
groupBy:
- lastEvent.log.hostname
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ afterEvents:
- field: log.processName
operator: filter_term
value: '{{.log.processName}}'
within: now-30m
within: 30m
count: 2
groupBy:
- lastEvent.log.exploitTechnique
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.headHostname
operator: filter_term
value: '{{.log.headHostname}}'
within: now-30m
within: 30m
count: 3
groupBy:
- lastEvent.log.headHostname
Expand Down
2 changes: 1 addition & 1 deletion rules/antivirus/esmc-eset/eset_console_abuse.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.headHostname
operator: filter_term
value: '{{.log.headHostname}}'
within: now-30m
within: 30m
count: 10
groupBy:
- lastEvent.log.headHostname
Expand Down
2 changes: 1 addition & 1 deletion rules/antivirus/esmc-eset/eset_quarantine_failures.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ afterEvents:
- field: log.headHostname
operator: filter_term
value: '{{.log.headHostname}}'
within: now-1h
within: 1h
count: 5
groupBy:
- lastEvent.log.headHostname
Expand Down
2 changes: 1 addition & 1 deletion rules/antivirus/kaspersky/data_exfiltration_attempts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ afterEvents:
- field: log.cat
operator: filter_term
value: NetworkThreat
within: now-30m
within: 30m
count: 5
groupBy:
- origin.ip
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -36,5 +36,5 @@ afterEvents:
- field: log.src
operator: filter_term
value: '{{.log.src}}'
within: now-10m
within: 10m
count: 3
2 changes: 1 addition & 1 deletion rules/antivirus/kaspersky/lateral_movement_indicators.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,5 +41,5 @@ afterEvents:
- field: log.src
operator: filter_term
value: '{{.log.src}}'
within: now-2h
within: 2h
count: 3
2 changes: 1 addition & 1 deletion rules/antivirus/kaspersky/suspicious_network_activity.yml
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ afterEvents:
- field: log.dstIP
operator: filter_term
value: '{{.log.dstIP}}'
within: now-30m
within: 30m
count: 5
groupBy:
- target.ip
2 changes: 1 addition & 1 deletion rules/cisco/asa/ips_signature_matches.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ afterEvents:
- field: origin.ip
operator: filter_term
value: '{{.origin.ip}}'
within: now-15m
within: 15m
count: 3
groupBy:
- adversary.ip
Expand Down
8 changes: 4 additions & 4 deletions rules/cisco/asa/multiple_failed_vpn_attempts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ afterEvents:
- field: log.messageId
operator: filter_term
value: '113015'
within: now-15m
within: 15m
count: 10
or:
- indexPattern: v11-log-firewall-cisco-asa-*
Expand All @@ -51,7 +51,7 @@ afterEvents:
- field: log.messageId
operator: filter_term
value: '113021'
within: now-15m
within: 15m
count: 10
- indexPattern: v11-log-firewall-cisco-asa-*
with:
Expand All @@ -61,7 +61,7 @@ afterEvents:
- field: log.messageId
operator: filter_term
value: '109034'
within: now-15m
within: 15m
count: 10
- indexPattern: v11-log-firewall-cisco-asa-*
with:
Expand All @@ -71,7 +71,7 @@ afterEvents:
- field: log.messageId
operator: filter_term
value: '611102'
within: now-15m
within: 15m
count: 10
groupBy:
- adversary.ip
Expand Down
2 changes: 1 addition & 1 deletion rules/cisco/cs_switch/arp_poisoning_detection.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: origin.ip
operator: filter_term
value: '{{.origin.ip}}'
within: now-10m
within: 10m
count: 5
groupBy:
- adversary.ip
Expand Down
2 changes: 1 addition & 1 deletion rules/cisco/cs_switch/mac_address_spoofing.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: origin.mac
operator: filter_term
value: '{{.origin.mac}}'
within: now-10m
within: 10m
count: 3
groupBy:
- adversary.mac
2 changes: 1 addition & 1 deletion rules/cisco/firepower/c2_nonstandard_port.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ afterEvents:
- field: target.ip
operator: filter_term
value: '{{.target.ip}}'
within: now-1h
within: 1h
count: 5
groupBy:
- adversary.ip
Expand Down
2 changes: 1 addition & 1 deletion rules/cisco/meraki/meraki_vpn_brute_force.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ afterEvents:
- field: origin.ip
operator: filter_term
value: '{{.origin.ip}}'
within: now-15m
within: 15m
count: 10
groupBy:
- adversary.ip
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/aws_ecs_credential_theft.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'ecs.amazonaws.com'
within: now-30m
within: 30m
count: 5
groupBy:
- adversary.user
Expand Down
6 changes: 3 additions & 3 deletions rules/cloud/aws/aws/aws_golden_saml_attack.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,22 +34,22 @@ afterEvents:
- field: log.userIdentityAccountId
operator: filter_term
value: '{{.log.userIdentityAccountId}}'
within: now-24h
within: 24h
count: 1
or:
- indexPattern: v11-log-aws-*
with:
- field: log.eventName
operator: filter_term
value: 'UpdateSAMLProvider'
within: now-24h
within: 24h
count: 1
- indexPattern: v11-log-aws-*
with:
- field: log.eventName
operator: filter_term
value: 'CreateSAMLProvider'
within: now-24h
within: 24h
count: 1
groupBy:
- adversary.user
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/aws_securityhub_finding_evasion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'securityhub.amazonaws.com'
within: now-30m
within: 30m
count: 5
groupBy:
- adversary.user
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/aws_ssm_sendcommand_abuse.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'ssm.amazonaws.com'
within: now-30m
within: 30m
count: 5
groupBy:
- adversary.user
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/aws_sso_suspicious_activities.yml
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'sso.amazonaws.com'
within: now-30m
within: 30m
count: 10
groupBy:
- lastEvent.log.sourceIPAddress
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/cloudformation_stack_deletion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'cloudformation.amazonaws.com'
within: now-30m
within: 30m
count: 5
groupBy:
- lastEvent.log.userIdentityAccountId
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/console_login_impossible_travel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ afterEvents:
- field: origin.geolocation.countryCode
operator: must_not_term
value: '{{.origin.geolocation.countryCode}}'
within: now-30m
within: 30m
count: 1
groupBy:
- adversary.user
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/cross_account_access_anomalies.yml
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ afterEvents:
- field: log.eventName
operator: filter_term
value: 'AssumeRole'
within: now-15m
within: 15m
count: 15
groupBy:
- lastEvent.log.responseElementsAssumedRoleUserArn
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/iam_backdoor_creation_attempts.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: 'iam.amazonaws.com'
within: now-30m
within: 30m
count: 3
groupBy:
- lastEvent.log.sourceIPAddress
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/iam_privilege_escalation_paths.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ afterEvents:
- field: log.eventSource
operator: filter_term
value: iam.amazonaws.com
within: now-30m
within: 30m
count: 3
groupBy:
- adversary.user
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/lambda_privilege_escalation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ afterEvents:
- field: log.eventName
operator: filter_term
value: AttachRolePolicy
within: now-1h
within: 1h
count: 2
groupBy:
- lastEvent.log.requestParameters.roleArn
Expand Down
2 changes: 1 addition & 1 deletion rules/cloud/aws/aws/mass_resource_deletion.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ afterEvents:
- field: log.userIdentity.arn
operator: filter_term
value: '{{.log.userIdentity.arn}}'
within: now-10m
within: 10m
count: 15
groupBy:
- lastEvent.log.sourceIPAddress
Expand Down
Loading
Loading