Commit Graph

24 Commits

Author SHA1 Message Date
thomashaw
df0c7c5f33 EA access_acc rule update (covers su account & exploit acc access via distccd) 2022-10-19 16:47:06 +01:00
thomashaw
66c83feee9 Updating EA rule to correctly works with OR clause for different process.executable's (wip2) 2022-10-15 21:13:01 +01:00
thomashaw
27ac703e61 Updating EA rule to correctly works with OR clause for different process.executable's (wip) 2022-10-15 18:01:55 +01:00
thomashaw
d6431ae991 Updating EA rule to correctly works with OR clause for different process.executable's 2022-10-15 16:34:28 +01:00
thomashaw
dfc73ba2ca web_test -- test if it works w/ proxy or not 2022-07-10 17:27:04 +01:00
thomashaw
f7e7747dee simplified rule for testing / benchmarking 2022-07-10 16:59:58 +01:00
thomashaw
614ddcce67 wip 2022-07-07 23:06:36 +01:00
thomashaw
dc1e2cba25 wip 2022-07-07 23:03:06 +01:00
thomashaw
ca1701a86e wip 2022-07-07 22:38:42 +01:00
thomashaw
7212a5980f wip 2022-07-07 22:13:17 +01:00
thomashaw
4307d4a117 wip 2022-07-07 21:59:55 +01:00
thomashaw
0cf678ffb5 print 2022-07-07 21:43:23 +01:00
thomashaw
3339432d9b Fixing scenario + adding an error message for if a file within '/' is monitored as a goal. 2022-04-21 15:15:57 +01:00
thomashaw
e0929bf4cc updated EA rule generation to add switch 2022-04-20 14:16:58 +01:00
thomashaw
fae33e2140 updating EA rule generation to include file name 2022-04-20 12:47:41 +01:00
thomashaw
d2b31ecfbf updated elastalert rule execalerter to include 'raise' keyword 2022-04-19 16:12:25 +01:00
thomashaw
59884a72f9 updating generated rule format and rule target paths 2022-02-24 17:23:11 +00:00
thomashaw
08507e2fe8 updated rule generation + left comment in for testing. (3/?) 2022-02-23 15:07:40 +00:00
thomashaw
475149da1a updated rule generation + left comment in for testing. (2/?) 2022-02-23 15:07:07 +00:00
thomashaw
2feb7611c2 updated rule generation + left comment in for testing. 2022-02-22 21:45:27 +00:00
thomashaw
a15fbf9847 updated rule. needs testing 2022-02-22 21:04:44 +00:00
thomashaw
17318c08b8 updated rule. needs testing 2022-02-22 21:04:20 +00:00
thomashaw
5d193d382d Adding the account access rule template... 2022-02-16 17:04:29 +00:00
thomashaw
0a06435dc9 big_merge 2021-11-22 16:26:34 +00:00