[SIEM][Detection Rules] Add 7.9 rules#71332
[SIEM][Detection Rules] Add 7.9 rules#71332rw-access merged 10 commits intoelastic:masterfrom rw-access:rules/7.9
Conversation
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/notice.ts
Outdated
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Outdated
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Outdated
Show resolved
Hide resolved
x-pack/plugins/security_solution/server/lib/detection_engine/rules/prepackaged_rules/index.ts
Show resolved
Hide resolved
|
Versioning looks solid for all of the rules 👍 |
...ution/server/lib/detection_engine/rules/prepackaged_rules/windows_suspicious_pdf_reader.json
Show resolved
Hide resolved
brokensound77
left a comment
There was a problem hiding this comment.
Versioning, autogenerated files, and renames all seem to have worked nicely.
LGTM once it passes 👍
spong
left a comment
There was a problem hiding this comment.
LGTM! Was able to verify successful POST of the Elastic Endpoint and External Alerts rules without issue. Skimmed the other changes and those look good as well. Thanks @rw-access! 🙂
|
@elasticmachine merge upstream |
|
@rw-access @brokensound77 -- needed to run |
|
@elasticmachine merge upstream |
|
Twas a twofer:
|
|
@elasticmachine merge upstream |
💚 Build SucceededBuild metrics
History
To update your PR or re-run it, just comment with: |
Summary
Add rules from detection-rules
Checklist
N/A
For maintainers