Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

more correlation rules from AWS re:inforce #1289

Merged
merged 3 commits into from
Sep 16, 2024
Merged

Conversation

arielkr256
Copy link
Contributor

Background

Additional correlation rules from AWS re:inforce. Pending absence:true test cases

Changes

  • 2 more correlation rules

Testing

Copy link

😱
looks like some things could be wrong with the packs

[INFO][root]: ignoring file dependabot.yml

@arielkr256 arielkr256 added the enhancement New feature or request label Sep 4, 2024
@arielkr256 arielkr256 added scheduled_rules Scheduled rules pair Queries with Rules for query based detections and removed enhancement New feature or request labels Sep 11, 2024
@arielkr256 arielkr256 marked this pull request as ready for review September 16, 2024 20:22
@arielkr256 arielkr256 requested a review from a team as a code owner September 16, 2024 20:22
@arielkr256 arielkr256 enabled auto-merge (squash) September 16, 2024 20:43
@arielkr256 arielkr256 merged commit 6404644 into release Sep 16, 2024
7 checks passed
@arielkr256 arielkr256 deleted the aws-crs-part2 branch September 16, 2024 20:44
arielkr256 added a commit that referenced this pull request Sep 16, 2024
* more correlation rules from AWS re:inforce

* unit tests
arielkr256 added a commit that referenced this pull request Sep 16, 2024
* traildiscover enrichment with managed schema (#1177)

* traildiscover enrichment with managed schema

* Add npm install in dockerfile (#1172)

* add npm install in dockerfile

* Remove Python optimizations; add prettier to PATH

---------

Co-authored-by: egibs <[email protected]>

* schema name: TrailDiscover.CloudTrail

* Fix Dockerfile; add Workflow to test image

* updated data set

* Add MongoDB.2FA.Disabled rule (#1190)

Co-authored-by: Ariel Ropek <[email protected]>

* lint and fmt

* fmt

* add OCSF selector

* additional OCSF mappings

* Fix Pipfile

* Rebase changes

---------

Co-authored-by: Panos Sakkos <[email protected]>
Co-authored-by: egibs <[email protected]>
Co-authored-by: Oleh Melenevskyi <[email protected]>

* Update PAT to 0.46.0 (#1216)

* sample_logs

* Wiz Audit rules (without Mitre mappings, Severities and Runbooks)

* Wiz Audit rules (updated Mitre mappings, Severities and Runbooks)

* Validate on PR approval (#1354)

* more correlation rules from AWS re:inforce (#1289)

* more correlation rules from AWS re:inforce

* unit tests

* MITRE ATT&CK and severity

* packs

* pipfile update

* update

* pipfile

* fix upload

---------

Co-authored-by: Ariel Ropek <[email protected]>
Co-authored-by: Panos Sakkos <[email protected]>
Co-authored-by: egibs <[email protected]>
Co-authored-by: Oleh Melenevskyi <[email protected]>
Co-authored-by: Evan Gibler <[email protected]>
Co-authored-by: Ariel Ropek <[email protected]>
@arielkr256 arielkr256 added correlation_rules Correlation rules establish correlations across logs, identify anomalies, and model complex attack b and removed scheduled_rules Scheduled rules pair Queries with Rules for query based detections labels Sep 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
correlation_rules Correlation rules establish correlations across logs, identify anomalies, and model complex attack b
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants