Elastic Rules

1. 介绍

内置100+检测规则可直接使用,如下图: nDBkDF

2. 案例

检测计划任务(scheduled task)是否被创建

iam where event.action == "scheduled-task-created" and /* excluding
tasks created by the computer account */ not : "*$" and
/* TaskContent is not parsed, exclude by full taskname noisy ones */
not winlog.event_data.TaskName : ("\\OneDrive Standalone
Update Task-S-1-5-21*", "\\Hewlett-Packard\\HP Web
Products Detection", "\\Hewlett-Packard\\HPDeviceCheck")

3. 参考资料

Last updated on 4/9/2023