Cyb3rWard0g / HELK

The Hunting ELK
GNU General Public License v3.0
3.73k stars 675 forks source link

Added two native Elastalert rules to the repo #504

Closed svch0stz closed 3 years ago

svch0stz commented 3 years ago

What is this PR for? Additional of two native Elastalert rules to the repo. (sigmac conversion not currently working correctly so I've created these for now)

What type of PR is it? HELK Elastalert rules

How should this be tested?

Tested by replaying events.

PLEASE NOTE : to replay events with elastalert, you will need add the following line to the rule being tested before replaying so elastalert is looking at the timestamp of ingestion:

Questions:

Cyb3rWard0g commented 3 years ago

Thank you @svch0stz ! :)