elastic / detection-rules

Home Page:https://www.elastic.co/guide/en/security/current/detection-engine-overview.html

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[New Rule] Add Extensions to WSL Rule

Aegrah opened this issue · comments

Summary

Based on comment #3354 (comment), @w0rk3r and I discussed to add new WSL rules in the future. This issue is created to track these new rules.

The following activity through WSL could be added:

  • Tunneling
  • Specific suspicious tooling
  • File alterations in suspicious directories

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.