thomashaw
|
df0c7c5f33
|
EA access_acc rule update (covers su account & exploit acc access via distccd)
|
2022-10-19 16:47:06 +01:00 |
|
thomashaw
|
66c83feee9
|
Updating EA rule to correctly works with OR clause for different process.executable's (wip2)
|
2022-10-15 21:13:01 +01:00 |
|
thomashaw
|
27ac703e61
|
Updating EA rule to correctly works with OR clause for different process.executable's (wip)
|
2022-10-15 18:01:55 +01:00 |
|
thomashaw
|
d6431ae991
|
Updating EA rule to correctly works with OR clause for different process.executable's
|
2022-10-15 16:34:28 +01:00 |
|
thomashaw
|
dfc73ba2ca
|
web_test -- test if it works w/ proxy or not
|
2022-07-10 17:27:04 +01:00 |
|
thomashaw
|
f7e7747dee
|
simplified rule for testing / benchmarking
|
2022-07-10 16:59:58 +01:00 |
|
thomashaw
|
614ddcce67
|
wip
|
2022-07-07 23:06:36 +01:00 |
|
thomashaw
|
dc1e2cba25
|
wip
|
2022-07-07 23:03:06 +01:00 |
|
thomashaw
|
ca1701a86e
|
wip
|
2022-07-07 22:38:42 +01:00 |
|
thomashaw
|
7212a5980f
|
wip
|
2022-07-07 22:13:17 +01:00 |
|
thomashaw
|
4307d4a117
|
wip
|
2022-07-07 21:59:55 +01:00 |
|
thomashaw
|
0cf678ffb5
|
print
|
2022-07-07 21:43:23 +01:00 |
|
thomashaw
|
3339432d9b
|
Fixing scenario + adding an error message for if a file within '/' is monitored as a goal.
|
2022-04-21 15:15:57 +01:00 |
|
thomashaw
|
e0929bf4cc
|
updated EA rule generation to add switch
|
2022-04-20 14:16:58 +01:00 |
|
thomashaw
|
fae33e2140
|
updating EA rule generation to include file name
|
2022-04-20 12:47:41 +01:00 |
|
thomashaw
|
d2b31ecfbf
|
updated elastalert rule execalerter to include 'raise' keyword
|
2022-04-19 16:12:25 +01:00 |
|
thomashaw
|
59884a72f9
|
updating generated rule format and rule target paths
|
2022-02-24 17:23:11 +00:00 |
|
thomashaw
|
08507e2fe8
|
updated rule generation + left comment in for testing. (3/?)
|
2022-02-23 15:07:40 +00:00 |
|
thomashaw
|
475149da1a
|
updated rule generation + left comment in for testing. (2/?)
|
2022-02-23 15:07:07 +00:00 |
|
thomashaw
|
2feb7611c2
|
updated rule generation + left comment in for testing.
|
2022-02-22 21:45:27 +00:00 |
|
thomashaw
|
a15fbf9847
|
updated rule. needs testing
|
2022-02-22 21:04:44 +00:00 |
|
thomashaw
|
17318c08b8
|
updated rule. needs testing
|
2022-02-22 21:04:20 +00:00 |
|
thomashaw
|
5d193d382d
|
Adding the account access rule template...
|
2022-02-16 17:04:29 +00:00 |
|
thomashaw
|
0a06435dc9
|
big_merge
|
2021-11-22 16:26:34 +00:00 |
|