Skip to content

Commit

Permalink
Merge branch 'main' into onweek_research
Browse files Browse the repository at this point in the history
  • Loading branch information
shashank-elastic authored Dec 2, 2024
2 parents c0d3c3b + 86cc61c commit 233d465
Show file tree
Hide file tree
Showing 68 changed files with 931 additions and 152 deletions.
807 changes: 732 additions & 75 deletions detection_rules/etc/version.lock.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
[project]
name = "detection_rules"
version = "0.2.0"
version = "0.2.1"
description = "Detection Rules is the home for rules used by Elastic Security. This repository is used for the development, maintenance, testing, validation, and release of rules for Elastic Security’s Detection Engine."
readme = "README.md"
requires-python = ">=3.12"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/08/29"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
4 changes: 3 additions & 1 deletion rules/integrations/github/execution_github_app_deleted.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/10/11"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/10/11"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/08/29"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/08/29"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/09/11"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/09/11"
integration = ["github"]
maturity = "production"
updated_date = "2024/05/21"
updated_date = "2024/11/27"
min_stack_version = "8.12.0"
min_stack_comments = "Breaking change at 8.12.0 for the Github Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/08/19"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic", "@BenB196", "Austin Songer"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/11/10"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
creation_date = "2023/11/08"
integration = ["okta"]
maturity = "production"
min_stack_comments = "ES|QL rule type becomes available in 8.13.0 as technical preview."
min_stack_version = "8.13.0"
updated_date = "2024/10/09"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."
min_stack_version = "8.14.0"
updated_date = "2024/11/27"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
creation_date = "2024/06/17"
integration = ["okta"]
maturity = "production"
min_stack_comments = "ES|QL rule type becomes available in 8.13.0 as technical preview."
min_stack_version = "8.13.0"
updated_date = "2024/10/09"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."
min_stack_version = "8.14.0"
updated_date = "2024/11/27"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
creation_date = "2024/06/17"
integration = ["okta"]
maturity = "production"
min_stack_comments = "ES|QL rule type becomes available in 8.13.0 as technical preview."
min_stack_version = "8.13.0"
updated_date = "2024/10/09"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."
min_stack_version = "8.14.0"
updated_date = "2024/11/27"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/07/16"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2023/11/18"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@
creation_date = "2024/06/17"
integration = ["okta"]
maturity = "production"
min_stack_comments = "ES|QL rule type becomes available in 8.13.0 as technical preview."
min_stack_version = "8.13.0"
updated_date = "2024/10/09"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."
min_stack_version = "8.14.0"
updated_date = "2024/11/27"

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2022/01/05"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2022/03/22"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2024/09/11"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/28"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/08/19"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic", "@BenB196", "Austin Songer"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/11/06"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
4 changes: 3 additions & 1 deletion rules/integrations/okta/impact_possible_okta_dos_attack.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,9 @@
creation_date = "2020/05/21"
integration = ["okta"]
maturity = "production"
updated_date = "2024/09/23"
updated_date = "2024/11/27"
min_stack_version = "8.14.0"
min_stack_comments = "Breaking change at 8.14.0 for the Okta Integration."

[rule]
author = ["Elastic"]
Expand Down
Loading

0 comments on commit 233d465

Please sign in to comment.