-
Notifications
You must be signed in to change notification settings - Fork 188
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adding Documents for v7.16.4 Pre-Built Detection Rules Integration Release #2367
Conversation
@jmikell821 sorry about that, this should merge into 7.17 and includes the correct updated files. Ready when you have time for review! |
@jmikell821 this PR is ready for merging and backporting when you have time. Please let me know if you have any questions and enjoy your weekend! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I managed to get through the rules for AWS, Azure, and GCP, and I'm submitting the review to make sure my comments don't get lost (sometimes happens with large PRs).
docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc
Outdated
Show resolved
Hide resolved
...-packages/7-16-4/prebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc
Outdated
Show resolved
Hide resolved
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Outdated
Show resolved
Hide resolved
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Outdated
Show resolved
Hide resolved
.../downloadable-packages/7-16-4/prebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc
Outdated
Show resolved
Hide resolved
...t-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc
Outdated
Show resolved
Hide resolved
...les/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc
Outdated
Show resolved
Hide resolved
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Show resolved
Hide resolved
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Outdated
Show resolved
Hide resolved
...ckages/7-16-4/prebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc
Outdated
Show resolved
Hide resolved
…ates.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
@joepeeples thanks for all the wonderful suggestions! These have been addressed and resolved. |
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Outdated
Show resolved
Hide resolved
...etections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc
Outdated
Show resolved
Hide resolved
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
…ebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
…lease (elastic#2367) * adding documents for v7.16.4 pre-built detection rules * Update docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
…lease (#2367) (#2414) * adding documents for v7.16.4 pre-built detection rules * Update docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc Co-authored-by: Joe Peeples <joe.peeples@elastic.co> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> * Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> Co-authored-by: Joe Peeples <joe.peeples@elastic.co> Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Security Doc updates for integrations (v7.16.4) rule changes in 8.4 release. Please note these are meant to merge into 7.17 for 7.x series only and backport to 7.16.
Preview: https://security-docs_2367.docs-preview.app.elstc.co/guide/en/security/7.17/prebuilt-rule-7-16-4-prebuilt-rules-7-16-4-summary.html
Important Checks:
index.asciidoc
addedindex.asciidoc
containsprebuilt-rules-7-16-4-appendix.asciidoc[]
entryprebuilt-rules-downloadable-updates.asciidoc
addedprebuilt-rules-downloadable-updates.asciidoc
contains new entry for 7.16.4 and includes summary asciidoc reference