elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[New] Attempt to establish VScode Remote Tunnel #4061

Closed Samirbous closed 3 weeks ago

Samirbous commented 4 weeks ago

https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/

converted one our ER diag rules to SIEM which covers this technique.

protectionsmachine commented 4 weeks ago

Rule: New - Guidelines

These guidelines serve as a reminder set of considerations when proposing a new rule.

Documentation and Context

Rule Metadata Checks

New BBR Rules

Testing and Validation