-
Notifications
You must be signed in to change notification settings - Fork 8.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[SIEM][Detection Rules] Add 7.9 rules #71332
Conversation
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/notice.ts
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Outdated
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Outdated
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Show resolved
Hide resolved
Versioning looks solid for all of the rules 👍 |
...ution/server/lib/detection_engine/rules/prepackaged_rules/windows_suspicious_pdf_reader.json
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Versioning, autogenerated files, and renames all seem to have worked nicely.
LGTM once it passes 👍
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM! Was able to verify successful POST
of the Elastic Endpoint
and External Alerts
rules without issue. Skimmed the other changes and those look good as well. Thanks @rw-access! 🙂
@elasticmachine merge upstream |
@rw-access @brokensound77 -- needed to run |
@elasticmachine merge upstream |
Twas a twofer:
|
@elasticmachine merge upstream |
💚 Build SucceededBuild metrics
History
To update your PR or re-run it, just comment with: |
Summary
Add rules from detection-rules
Checklist
N/A
For maintainers