elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[New Rule] SSL Certificate Deletion #4026

Closed Aegrah closed 1 month ago

Aegrah commented 1 month ago

Summary

This rule detects the deletion of SSL certificates on a Linux system. Adversaries may delete SSL certificates to subvert trust controls and negatively impact the system.

Telemetry

This behavior is not inherently malicious, so telemetry shows 70 hits last 90d. I bumped it to low, rather than BBR, because it is a note worthy event.

One TP in detonate stack:

{1DC55ADF-E31A-4B9E-A62D-57490A698948}
protectionsmachine commented 1 month ago

Rule: New - Guidelines

These guidelines serve as a reminder set of considerations when proposing a new rule.

Documentation and Context

Rule Metadata Checks

New BBR Rules

Testing and Validation