-
Notifications
You must be signed in to change notification settings - Fork 427
New Rules & Updates - Oct 25 #3726
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
+1,597
−371
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
detections/endpoint/file_download_or_read_to_pipe_execution.yml
Outdated
Show resolved
Hide resolved
neat PR description and updates!
patel-bhavin
patel-bhavin
approved these changes
Oct 24, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.
This PR introduces a couple new analytics, fixes some reported issues and add multiple updates. See below for details:
Adding Missing Data Sources
The first set of update is to a bunch of rules that had an DS defined but not linked in the rule. Now this is fixed (the rest of the rules either are experimental and/or have no DS defined).
New Rules
Rule Updates / Issues Fixes
Detect New Local Admin accountby adding the raw fieldTargetUserNamein the condition in order to provide a generic fix for [BUG] Detect New Local Admin Account #3730Dump LSASS via procdumpwith additional flags and process namesPowershell Disable Security Monitoringwith additional Cmdlet and their aliases as well as enhanced the logic to be more accurateWeb or Application Server Spawning a Shellby adding wildcards to some process names to be more genericWindows AdFind Exeto be more generic and capture more common abuse vectors as reported by various threat intel sources.Windows EventLog Recon Activity Using Log Query Utilitiesby adding OriginalFileName fields for better coverage.Windows File Transfer Protocol In Non-Common Process PathandWindows Mail Protocol In Non-Common Process Pathin order to reduce FPWindows SSH Proxy Commanby adding new variants of execution.Detect Regasm with Network Connection,Detect Regsvcs with Network Connection,LOLBAS With Network Traffic,Lookup Updates
cisco_secure_firewall_filetype_lookup- Added untruffled Arcan Door ruleis_nirsoft_software- Add wildcards and additional nirsoft toolingMacro Updates
windows_shells- Reworked the logic to use theINoperator for ease of reading, also addedpowershell_ise,WindowsTerminal,wtandmshtaDeprecated Rules