elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Attempt to Disable IPTables or Firewall #3972

Closed Aegrah closed 1 month ago

Aegrah commented 2 months ago

Summary

While detonating malware in Detonate, I noticed we lacked coverage on several techniques to disable the firewall / flush the IPTables. This tuning PR adds additional coverage to the rule.

Detonate hits:

{27689E00-0CAA-4950-A629-BCB3C2CA532D}
protectionsmachine commented 2 months ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation