Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adding Documents for v7.16.4 Pre-Built Detection Rules Integration Release #2367

Merged
merged 34 commits into from
Aug 30, 2022

Conversation

terrancedejesus
Copy link
Contributor

@terrancedejesus terrancedejesus commented Aug 24, 2022

Security Doc updates for integrations (v7.16.4) rule changes in 8.4 release. Please note these are meant to merge into 7.17 for 7.x series only and backport to 7.16.

Preview: https://security-docs_2367.docs-preview.app.elstc.co/guide/en/security/7.17/prebuilt-rule-7-16-4-prebuilt-rules-7-16-4-summary.html

Important Checks:

  • index.asciidoc added
  • index.asciidoc contains prebuilt-rules-7-16-4-appendix.asciidoc[] entry
  • prebuilt-rules-downloadable-updates.asciidoc added
  • prebuilt-rules-downloadable-updates.asciidoc contains new entry for 7.16.4 and includes summary asciidoc reference
  • if 7.x series, merge points to 7.17 branch

@terrancedejesus
Copy link
Contributor Author

@jmikell821 sorry about that, this should merge into 7.17 and includes the correct updated files. Ready when you have time for review!

@terrancedejesus
Copy link
Contributor Author

@jmikell821 this PR is ready for merging and backporting when you have time. Please let me know if you have any questions and enjoy your weekend!

Copy link
Contributor

@joepeeples joepeeples left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I managed to get through the rules for AWS, Azure, and GCP, and I'm submitting the review to make sure my comments don't get lost (sometimes happens with large PRs).

terrancedejesus and others added 19 commits August 26, 2022 15:16
…ates.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
terrancedejesus and others added 11 commits August 29, 2022 10:09
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
…ebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
@terrancedejesus
Copy link
Contributor Author

@joepeeples thanks for all the wonderful suggestions! These have been addressed and resolved.
@jmikell821 once checks are done, these should be ready to merge and backport.

terrancedejesus and others added 2 commits August 30, 2022 12:01
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
…ebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
@jmikell821 jmikell821 merged commit 7f2f8d6 into 7.17 Aug 30, 2022
jmikell821 added a commit to jmikell821/security-docs that referenced this pull request Aug 30, 2022
…lease (elastic#2367)

* adding documents for v7.16.4 pre-built detection rules

* Update docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>
jmikell821 added a commit that referenced this pull request Sep 1, 2022
…lease (#2367) (#2414)

* adding documents for v7.16.4 pre-built detection rules

* Update docs/detections/prebuilt-rules/prebuilt-rules-downloadable-updates.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-potential-cookies-theft-via-browser-debugging.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-elastic-agent-service-terminated.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-sink-modification.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-microsoft-365-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-security-software-discovery-via-grep.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-access-secret-in-secrets-manager.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-config-resource-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-efs-file-system-or-mount-deleted.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-aws-route53-private-hosted-zone-associated-with-a-vpc.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-command-execution-on-virtual-machine.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-active-directory-high-risk-sign-in.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-ad-global-administrator-role-assigned.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-azure-global-administrator-role-addition-to-pim-user.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rule-7-16-4-gcp-logging-bucket-deletion.asciidoc

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

* Update docs/detections/prebuilt-rules/downloadable-packages/7-16-4/prebuilt-rules-7-16-4-summary.asciidoc

Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
Co-authored-by: Janeen Mikell-Straughn <57149392+jmikell821@users.noreply.github.com>

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
Co-authored-by: Joe Peeples <joe.peeples@elastic.co>
@terrancedejesus terrancedejesus deleted the add-integrations-7.16.4-rules branch September 18, 2023 22:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants