elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[New Rule] Access Control List Modification via setfacl #4009

Closed Aegrah closed 1 month ago

Aegrah commented 1 month ago

Summary

This BBR increases coverage for ACL modifications. This is not a malicious action but is used by malicious scripts (see ref) to modify file attributes.

This BBR is useful to just get an extra signal for instances where it might be used to evade detection.

protectionsmachine commented 1 month ago

Rule: New - Guidelines

These guidelines serve as a reminder set of considerations when proposing a new rule.

Documentation and Context

Rule Metadata Checks

New BBR Rules

Testing and Validation