You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<linkrel="next" href="aws-bedrock-detected-multiple-attempts-to-use-denied-models-by-a-single-user.html" title="AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User"/>
<ahref="a-scheduled-task-was-created.html">« A scheduled task was created</a>
114
114
</span>
115
115
<spanclass="next">
116
-
<ahref="aws-cloudtrail-log-created.html">AWS CloudTrail Log Created »</a>
116
+
<ahref="aws-bedrock-detected-multiple-attempts-to-use-denied-models-by-a-single-user.html">AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User »</a>
<ahref="a-scheduled-task-was-created.html">« A scheduled task was created</a>
264
264
</span>
265
265
<spanclass="next">
266
-
<ahref="aws-cloudtrail-log-created.html">AWS CloudTrail Log Created »</a>
266
+
<ahref="aws-bedrock-detected-multiple-attempts-to-use-denied-models-by-a-single-user.html">AWS Bedrock Detected Multiple Attempts to use Denied Models by a Single User »</a>
<h3class="title"><aid="_investigation_guide_55"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
199
+
<h3class="title"><aid="_investigation_guide_56"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
200
200
</div></div></div>
201
201
<p><spanclass="strong strong"><strong>Triage and analysis</strong></span></p>
202
202
<p><spanclass="strong strong"><strong>Investigating Abnormal Process ID or Lock File Created</strong></span></p>
<h3class="title"><aid="_setup_56"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
288
+
<h3class="title"><aid="_setup_59"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
<p>This rule requires data coming in from Elastic Defend.</p>
@@ -343,7 +343,7 @@ <h3 class="title"><a id="_setup_56"></a>Setup<a class="edit_me" rel="nofollow" t
343
343
344
344
<divclass="section">
345
345
<divclass="titlepage"><div><div>
346
-
<h3class="title"><aid="_rule_query_58"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
346
+
<h3class="title"><aid="_rule_query_62"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormal-process-id-or-lock-file-created.asciidoc">edit</a></h3>
347
347
</div></div></div>
348
348
<divclass="pre_wrapper lang-js">
349
349
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_investigation_guide_56"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormally-large-dns-response.asciidoc">edit</a></h3>
190
+
<h3class="title"><aid="_investigation_guide_57"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormally-large-dns-response.asciidoc">edit</a></h3>
191
191
</div></div></div>
192
192
<p><spanclass="strong strong"><strong>Triage and analysis</strong></span></p>
193
193
<p><spanclass="strong strong"><strong>Investigating Abnormally Large DNS Response</strong></span></p>
<h3class="title"><aid="_rule_query_59"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormally-large-dns-response.asciidoc">edit</a></h3>
261
+
<h3class="title"><aid="_rule_query_63"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/abnormally-large-dns-response.asciidoc">edit</a></h3>
262
262
</div></div></div>
263
263
<divclass="pre_wrapper lang-js">
264
264
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_rule_query_60"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/accepted-default-telnet-port-connection.asciidoc">edit</a></h3>
180
+
<h3class="title"><aid="_rule_query_64"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/accepted-default-telnet-port-connection.asciidoc">edit</a></h3>
181
181
</div></div></div>
182
182
<divclass="pre_wrapper lang-js">
183
183
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_setup_57"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-of-stored-browser-credentials.asciidoc">edit</a></h3>
178
+
<h3class="title"><aid="_setup_60"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-of-stored-browser-credentials.asciidoc">edit</a></h3>
<p>This rule requires data coming in from Elastic Defend.</p>
@@ -233,7 +233,7 @@ <h3 class="title"><a id="_setup_57"></a>Setup<a class="edit_me" rel="nofollow" t
233
233
234
234
<divclass="section">
235
235
<divclass="titlepage"><div><div>
236
-
<h3class="title"><aid="_rule_query_61"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-of-stored-browser-credentials.asciidoc">edit</a></h3>
236
+
<h3class="title"><aid="_rule_query_65"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-of-stored-browser-credentials.asciidoc">edit</a></h3>
237
237
</div></div></div>
238
238
<divclass="pre_wrapper lang-js">
239
239
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_setup_59"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-a-sensitive-ldap-attribute.asciidoc">edit</a></h3>
196
+
<h3class="title"><aid="_setup_62"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-a-sensitive-ldap-attribute.asciidoc">edit</a></h3>
<p>The <em>Audit Directory Service Access</em> logging policy must be configured for (Success, Failure).
@@ -210,7 +210,7 @@ <h3 class="title"><a id="_setup_59"></a>Setup<a class="edit_me" rel="nofollow" t
210
210
211
211
<divclass="section">
212
212
<divclass="titlepage"><div><div>
213
-
<h3class="title"><aid="_rule_query_63"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-a-sensitive-ldap-attribute.asciidoc">edit</a></h3>
213
+
<h3class="title"><aid="_rule_query_67"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-a-sensitive-ldap-attribute.asciidoc">edit</a></h3>
214
214
</div></div></div>
215
215
<divclass="pre_wrapper lang-js">
216
216
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_setup_58"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-keychain-credentials-directories.asciidoc">edit</a></h3>
181
+
<h3class="title"><aid="_setup_61"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-keychain-credentials-directories.asciidoc">edit</a></h3>
<p>This rule requires data coming in from Elastic Defend.</p>
@@ -236,7 +236,7 @@ <h3 class="title"><a id="_setup_58"></a>Setup<a class="edit_me" rel="nofollow" t
236
236
237
237
<divclass="section">
238
238
<divclass="titlepage"><div><div>
239
-
<h3class="title"><aid="_rule_query_62"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-keychain-credentials-directories.asciidoc">edit</a></h3>
239
+
<h3class="title"><aid="_rule_query_66"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/access-to-keychain-credentials-directories.asciidoc">edit</a></h3>
240
240
</div></div></div>
241
241
<divclass="pre_wrapper lang-js">
242
242
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_rule_query_64"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/accessing-outlook-data-files.asciidoc">edit</a></h3>
174
+
<h3class="title"><aid="_rule_query_68"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/accessing-outlook-data-files.asciidoc">edit</a></h3>
175
175
</div></div></div>
176
176
<divclass="pre_wrapper lang-js">
177
177
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_investigation_guide_57"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-configured-with-never-expiring-password.asciidoc">edit</a></h3>
193
+
<h3class="title"><aid="_investigation_guide_58"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-configured-with-never-expiring-password.asciidoc">edit</a></h3>
194
194
</div></div></div>
195
195
<p><spanclass="strong strong"><strong>Triage and analysis</strong></span></p>
196
196
<p><spanclass="strong strong"><strong>Investigating Account Configured with Never-Expiring Password</strong></span></p>
<h3class="title"><aid="_rule_query_65"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-configured-with-never-expiring-password.asciidoc">edit</a></h3>
260
+
<h3class="title"><aid="_rule_query_69"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-configured-with-never-expiring-password.asciidoc">edit</a></h3>
261
261
</div></div></div>
262
262
<divclass="pre_wrapper lang-js">
263
263
<divclass="console_code_copy" title="Copy to clipboard"></div>
<h3class="title"><aid="_investigation_guide_58"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
186
+
<h3class="title"><aid="_investigation_guide_59"></a>Investigation guide<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
187
187
</div></div></div>
188
188
<p><spanclass="strong strong"><strong>Triage and analysis</strong></span></p>
189
189
<p><spanclass="strong strong"><strong>Investigating Account Discovery Command via SYSTEM Account</strong></span></p>
<h3class="title"><aid="_setup_60"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
247
+
<h3class="title"><aid="_setup_63"></a>Setup<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
<p>If enabling an EQL rule on a non-elastic-agent index (such as beats) for versions <8.2,
@@ -256,7 +256,7 @@ <h3 class="title"><a id="_setup_60"></a>Setup<a class="edit_me" rel="nofollow" t
256
256
257
257
<divclass="section">
258
258
<divclass="titlepage"><div><div>
259
-
<h3class="title"><aid="_rule_query_66"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
259
+
<h3class="title"><aid="_rule_query_70"></a>Rule query<aclass="edit_me" rel="nofollow" title="Edit this page on GitHub" href="https://github.com/elastic/security-docs/edit/8.13/docs/detections/prebuilt-rules/rule-details/account-discovery-command-via-system-account.asciidoc">edit</a></h3>
260
260
</div></div></div>
261
261
<divclass="pre_wrapper lang-js">
262
262
<divclass="console_code_copy" title="Copy to clipboard"></div>
0 commit comments