Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

3.57.0 Release #1291

Merged
merged 13 commits into from
Jul 16, 2024
Merged

3.57.0 Release #1291

merged 13 commits into from
Jul 16, 2024

Conversation

le4ker
Copy link
Member

@le4ker le4ker commented Jul 16, 2024

Background

Releasing 3.57.0 Detections

geoffg-sentry and others added 12 commits July 8, 2024 09:33
Explorer launching powershell isn't a critical alert. Explorer and CMD launching powershell are the two most common ways to execute the application.

Additionally, this relationship has nothing to do with linked FalconForce RunAs reference nor its underlying T1036.005 or T1134.002.

Either remove this entirely, or drop the severity of explorer/powershell to INFO.
Bumps [docker/setup-qemu-action](https://github.com/docker/setup-qemu-action) from 3.0.0 to 3.1.0.
- [Release notes](https://github.com/docker/setup-qemu-action/releases)
- [Commits](docker/setup-qemu-action@6882732...5927c83)

---
updated-dependencies:
- dependency-name: docker/setup-qemu-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ariel Ropek <[email protected]>
Bumps [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) from 3.3.0 to 3.4.0.
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](docker/setup-buildx-action@d70bba7...4fd8129)

---
updated-dependencies:
- dependency-name: docker/setup-buildx-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ariel Ropek <[email protected]>
* Update aws_guardduty_high_sev_findings.yml

Add additional runbook info for guardduty alert types

* Update aws_guardduty_med_sev_findings.yml

* Update aws_guardduty_low_sev_findings.yml
* GitHub advanced security change not followed by repo archived

* StopInstance FOLLOWED BY ModifyInstanceAttributes (correlation rule)

* GCP run.services.create Privilege Escalation - correlation rule

* GCP run.services.create Privilege Escalation - linter fix

* Add gcp_cloud_run_service_created.py changes

Signed-off-by: egibs <[email protected]>

* updated to follow CR style guide/best practices

* instance_ids as lists for comparison

* added unit tests to correlation rules

* updated packs

---------

Signed-off-by: egibs <[email protected]>
Co-authored-by: akozlovets098 <[email protected]>
Co-authored-by: Ariel Ropek <[email protected]>
Co-authored-by: Ben Airey <[email protected]>
Co-authored-by: Ariel Ropek <[email protected]>
* Update Action versions; use SHAs (#1231)

* Update Action versions; use SHAs

* Add dependabot.yml to keep Actions updated

* Update PAT to 0.49.0

* scheduled rules and correlation rule for
snowflake data exfiltration

* transition names

* updates to comply with CR style guide

* cleanup and pack update

* MITRE ATT&CK tags

---------

Co-authored-by: Evan Gibler <[email protected]>
Co-authored-by: Ben Airey <[email protected]>
* lower severity for sensor update requests

* update
* correlation rules from AWS re:inforce

* aws potentially compromised service role

* update to match style guide

* remove duplicated rule: iam key quarantine

* merge duplicate rules: iam user key created

* added unit tests for several rules

* style guide updates and consistency changes

* pack update

* MITRE ATT&CK tags

* updates

* signal update

---------

Co-authored-by: Ben Airey <[email protected]>
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 5.1.0 to 5.1.1.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](actions/setup-python@82c7e63...39cd149)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* basic info level crwd api token rules, could use a crowdstrike_event_streat_alert_context method once the key_value pairs from AuditKeyValues is settled for easier access

* changed to check bool

* added final newline

* lint and format

* deep_get cleanup

* another test

* pack and helpers

---------

Co-authored-by: Ariel Ropek <[email protected]>
Co-authored-by: Ariel Ropek <[email protected]>
* push security correlation rules

* added unit tests to correlation rules

* made linter happy

* style guide updates

* mitre tags

* Okta.Login.Success

* updating unit tests for Okta.Login.Success

---------

Co-authored-by: Ben Airey <[email protected]>
@le4ker le4ker requested a review from a team as a code owner July 16, 2024 15:14
Copy link

😱
looks like some things could be wrong with the packs

[INFO][root]: ignoring file dependabot.yml

@le4ker le4ker enabled auto-merge July 16, 2024 15:18
Copy link
Contributor

@ben-githubs ben-githubs left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good to go

@le4ker le4ker merged commit 0aee35c into main Jul 16, 2024
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants