Comments (3)
We have incorporated pkill and killall and modified the query
process where
/* net, sc or wmic stopping or deleting Elastic Agent on Windows */
(event.type == "start" and
process.name : ("net.exe", "sc.exe", "wmic.exe","powershell.exe","taskkill.exe","PsKill.exe","ProcessHacker.exe") and
process.args : ("stopservice","uninstall", "stop", "disabled","Stop-Process","terminate","suspend") and
process.args : ("elasticendpoint", "Elastic Agent","elastic-agent","elastic-endpoint"))
or
/* service or systemctl used to stop Elastic Agent on Linux */
(event.type == "end" and
(process.name : ("systemctl", "service") and
process.args : "elastic-agent" and
process.args : "stop")
or
/* pkill , killall used to stop Elastic Agent on Linux */
( event.type == "end" and process.name : ("pkill", "killall") and process.args: "elastic-agent")
or
/* Unload Elastic Agent extension on MacOS */
(process.name : "kextunload" and
process.args : "com.apple.iokit.EndpointSecurity" and
event.action : "end"))
This updated query will be pushed as part of 8.9.
from detection-rules.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
from detection-rules.
This has been closed due to inactivity. If you feel this is an error, please re-open and include a justifying comment.
from detection-rules.
Related Issues (20)
- [Bug] Update Index Check for Integration Packages HOT 1
- [FR] Add API auth to Kibana module
- [FR][DAC] Consideration: Add support for exceptions APIs in Kibana module
- [FR][DAC] Consideration: Add CLI commands for deprecate / disable rules HOT 1
- [Meta] EvilNoVNC Threat Detection Coverage Assessment
- [Rule Tuning] Suspicious Inter-Process Communication via Outlook HOT 2
- [Bug] Microsoft IIS Service Account Password Dumped doesn't match the command arg
- [Bug] schema should not allow `index` and `dataview`
- [Bug] PowerShell Suspicious Discovery Related Windows API Functions - not file.path not working as expected. HOT 3
- [Rule Tuning] Attempts to Brute Force a Microsoft 365 User Account HOT 2
- [Bug][DAC] Rule Threat Reference Fields Exported from Kibana Mismatch URL HOT 2
- Update MITRE ATT&CK to
- Update MITRE ATT&CK to v15.1.1. HOT 1
- [FR] Add support for Kibana Rule Type rule_default HOT 1
- [Meta] Active Directory Certificate Services (AD CS) - Part 1
- [Bug] Unit Tests with Git Breaks CI workflows for Wiped Forked Repos HOT 4
- [FR] Generate Release Docs for deprecated Rules
- [Deprecation] AWS EC2 Snapshot Activity
- [FR] Adopt DAC with current ruleset HOT 2
- Add Data Source: System tag to security rules which have logs-system.security* or logs-system.* index pattern [FR]
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from detection-rules.