文件最后提交记录最后更新时间
9 天前
9 天前
README

Elastic Security Malicious Behavior Protection Rules

Prebuilt high signal EQL rules that runs on the endpoint to disrupt malicious behavior, this layer of prevention equips Elastic Agent to protect Linux, Windows, and macOS hosts from a broad range of attack techniques with a major focus on the following tactics :

Prevention is achieved by pairing post-execution analytics with response actions to kill a specific process or a full process tree tailored to stop the adversary at the initial stages of the attack. Each protection rule is mapped to the most relevant MITRE ATT&CK tactic, technique and subtechnique.

The true positive rate that we aim to maintain is at least 70%, thus we prioritize analytics logic precision to reduce detection scope via prevention.

Another example of our commitment to openness in security is our existing public Detection Rules repository where we share EQL rules that run on the SIEM side, and that have a broader detection logic which make them more suitable for detection and hunting.

Latest Release

artifact version hash
production-rules-linux-v1 1.0.125 ecbdb3f1b339a61afa0d5eb47bab19f6b69a409796f9688fa16ee72a6890b98c
production-rules-macos-v1 1.0.125 d3e2e87d35924abd7c0a1c238b82790e126d9a435cc203e3b083fb7eb0a934d2
production-rules-windows-v1 1.0.125 dc2fe58209e9054060c492c4c02ba4ddb96f208eefb8aa40a0c9932f99785327

Rules Summary per Tactic

Note: New Production Rules since last version ('1.0.125', '1.0.124') by OS/MITRE Tactic.

Tactic Windows Linux macOS Total by Tactic
Credential Access 1 0 0 1
Defense Evasion 1 1 0 2
Total by OS 2 1 0 3

Note: Latest Total Production Rules by OS/MITRE Tactic.

Tactic Windows Linux macOS Total by Tactic
Collection 13 4 10 27
Command and Control 40 22 41 103
Credential Access 56 16 38 110
Defense Evasion 329 84 63 476
Discovery 20 5 3 28
Execution 101 68 106 275
Exfiltration 0 1 2 3
Impact 19 6 2 27
Initial Access 66 4 5 75
Lateral Movement 10 2 1 13
Persistence 61 28 21 110
Privilege Escalation 76 28 9 113
Total by OS 791 268 301 1360

MITRE ATT&CK Coverage

XDR MITRE scorecard (endpoint + endpoint-scoped SIEM)

  • Catalog: 61 parent techniques (Win/Linux/macOS under 8 scorecard tactics)
  • Covered (union): 49/61 (80.33%) — production endpoint rules plus production SIEM rules with metadata.integration including "endpoint" and/or index matching logs-endpoint.events*/ logs-endpoint.alerts*
  • Techniques — endpoint-only: 1, SIEM-only: 4, both: 44
  • Rules — production endpoint: 1322, SIEM (in-scope + MITRE): 1038

Uncovered scorecard techniques (12 distinct parents; listed under each tactic where ATT&CK places them)

  • Execution
    • T1674 Input Injection
  • Persistence
    • T1668 Exclusive Control
    • T1653 Power Settings
  • Defense Evasion
    • T1622 Debugger Evasion
    • T1678 Delay Execution
    • T1480 Execution Guardrails
    • T1207 Rogue Domain Controller
    • T1679 Selective Exclusion
    • T1221 Template Injection
  • Credential Access
    • T1111 Multi-Factor Authentication Interception
  • Impact
    • T1561 Disk Wipe
    • T1529 System Shutdown/Reboot