|
80 | 80 | "config": {
|
81 | 81 | "groups": [
|
82 | 82 | "security",
|
83 |
| - "pad" |
| 83 | + "pad", |
| 84 | + "windows" |
84 | 85 | ],
|
85 | 86 | "description": "Detects unusually high special logon events initiated by a user.",
|
86 | 87 | "analysis_config": {
|
|
117 | 118 | "config": {
|
118 | 119 | "groups": [
|
119 | 120 | "security",
|
120 |
| - "pad" |
| 121 | + "pad", |
| 122 | + "windows" |
121 | 123 | ],
|
122 | 124 | "description": "Detects unusually high special privilege use events initiated by a user.",
|
123 | 125 | "analysis_config": {
|
|
153 | 155 | "config": {
|
154 | 156 | "groups": [
|
155 | 157 | "security",
|
156 |
| - "pad" |
| 158 | + "pad", |
| 159 | + "windows" |
157 | 160 | ],
|
158 | 161 | "description": "Detects unusually high security group management events initiated by a user.",
|
159 | 162 | "analysis_config": {
|
|
189 | 192 | "config": {
|
190 | 193 | "groups": [
|
191 | 194 | "security",
|
192 |
| - "pad" |
| 195 | + "pad", |
| 196 | + "windows" |
193 | 197 | ],
|
194 | 198 | "description": "Detects unusually high security user account management events initiated by a user.",
|
195 | 199 | "analysis_config": {
|
|
224 | 228 | "config": {
|
225 | 229 | "groups": [
|
226 | 230 | "security",
|
227 |
| - "pad" |
| 231 | + "pad", |
| 232 | + "windows" |
228 | 233 | ],
|
229 | 234 | "description": "Detects an unusual privilege type assigned to a user.",
|
230 | 235 | "analysis_config": {
|
|
259 | 264 | "config": {
|
260 | 265 | "groups": [
|
261 | 266 | "security",
|
262 |
| - "pad" |
| 267 | + "pad", |
| 268 | + "windows" |
263 | 269 | ],
|
264 | 270 | "description": "Detects an unusual group name accessed by a user.",
|
265 | 271 | "analysis_config": {
|
|
295 | 301 | "config": {
|
296 | 302 | "groups": [
|
297 | 303 | "security",
|
298 |
| - "pad" |
| 304 | + "pad", |
| 305 | + "windows" |
299 | 306 | ],
|
300 | 307 | "description": "Detects an unusual device accessed by a user.",
|
301 | 308 | "analysis_config": {
|
|
331 | 338 | "config": {
|
332 | 339 | "groups": [
|
333 | 340 | "security",
|
334 |
| - "pad" |
| 341 | + "pad", |
| 342 | + "windows" |
335 | 343 | ],
|
336 | 344 | "description": "Detects an unusual source IP address accessed by a user.",
|
337 | 345 | "analysis_config": {
|
|
367 | 375 | "config": {
|
368 | 376 | "groups": [
|
369 | 377 | "security",
|
370 |
| - "pad" |
| 378 | + "pad", |
| 379 | + "windows" |
371 | 380 | ],
|
372 | 381 | "description": "Detects an unusual region name for a user.",
|
373 | 382 | "analysis_config": {
|
|
404 | 413 | "config": {
|
405 | 414 | "groups": [
|
406 | 415 | "security",
|
407 |
| - "pad" |
| 416 | + "pad", |
| 417 | + "linux" |
408 | 418 | ],
|
409 | 419 | "description": "Detects a spike in privileged commands executed by a user.",
|
410 | 420 | "analysis_config": {
|
|
438 | 448 | "config": {
|
439 | 449 | "groups": [
|
440 | 450 | "security",
|
441 |
| - "pad" |
| 451 | + "pad", |
| 452 | + "linux" |
442 | 453 | ],
|
443 | 454 | "description": "Detects a rare process executed by a user.",
|
444 | 455 | "analysis_config": {
|
|
472 | 483 | "config": {
|
473 | 484 | "groups": [
|
474 | 485 | "security",
|
475 |
| - "pad" |
| 486 | + "pad", |
| 487 | + "linux" |
476 | 488 | ],
|
477 |
| - "description": "Detects process command lines executed by a user with an abnormally high median entropy value", |
| 489 | + "description": "Detects process command lines executed by a user with an abnormally high median entropy value. This job requires some manual setup before it can run successfully, specifically adding custom field mappings for data coming from an ingest pipeline. Instructions for these steps are available in the package overview.", |
478 | 490 | "analysis_config": {
|
479 | 491 | "bucket_span": "30m",
|
480 | 492 | "detectors": [
|
|
506 | 518 | "config": {
|
507 | 519 | "groups": [
|
508 | 520 | "security",
|
509 |
| - "pad" |
| 521 | + "pad", |
| 522 | + "okta" |
510 | 523 | ],
|
511 | 524 | "description": "Detects spike in group membership change events by a user.",
|
512 | 525 | "analysis_config": {
|
|
542 | 555 | "config": {
|
543 | 556 | "groups": [
|
544 | 557 | "security",
|
545 |
| - "pad" |
| 558 | + "pad", |
| 559 | + "okta" |
546 | 560 | ],
|
547 | 561 | "description": "Detects spike in user lifecycle management change events by a user.",
|
548 | 562 | "analysis_config": {
|
|
578 | 592 | "config": {
|
579 | 593 | "groups": [
|
580 | 594 | "security",
|
581 |
| - "pad" |
| 595 | + "pad", |
| 596 | + "okta" |
582 | 597 | ],
|
583 | 598 | "description": "Detects spike in group privilege change events by a user.",
|
584 | 599 | "analysis_config": {
|
|
616 | 631 | "config": {
|
617 | 632 | "groups": [
|
618 | 633 | "security",
|
619 |
| - "pad" |
| 634 | + "pad", |
| 635 | + "okta" |
620 | 636 | ],
|
621 | 637 | "description": "Detects spike in group application assignment change events by a user.",
|
622 | 638 | "analysis_config": {
|
|
651 | 667 | "config": {
|
652 | 668 | "groups": [
|
653 | 669 | "security",
|
654 |
| - "pad" |
| 670 | + "pad", |
| 671 | + "okta" |
655 | 672 | ],
|
656 | 673 | "description": "Detects spike in group lifecycle change events by a user.",
|
657 | 674 | "analysis_config": {
|
|
686 | 703 | "config": {
|
687 | 704 | "groups": [
|
688 | 705 | "security",
|
689 |
| - "pad" |
| 706 | + "pad", |
| 707 | + "okta" |
690 | 708 | ],
|
691 | 709 | "description": "Detects an unusual sum of active sessions started by a user.",
|
692 | 710 | "analysis_config": {
|
|
720 | 738 | "config": {
|
721 | 739 | "groups": [
|
722 | 740 | "security",
|
723 |
| - "pad" |
| 741 | + "pad", |
| 742 | + "okta" |
724 | 743 | ],
|
725 | 744 | "description": "Detects an unusual source IP address accessed by a user.",
|
726 | 745 | "analysis_config": {
|
|
755 | 774 | "config": {
|
756 | 775 | "groups": [
|
757 | 776 | "security",
|
758 |
| - "pad" |
| 777 | + "pad", |
| 778 | + "okta" |
759 | 779 | ],
|
760 | 780 | "description": "Detects an unusual region name for a user.",
|
761 | 781 | "analysis_config": {
|
|
791 | 811 | "config": {
|
792 | 812 | "groups": [
|
793 | 813 | "security",
|
794 |
| - "pad" |
| 814 | + "pad", |
| 815 | + "okta" |
795 | 816 | ],
|
796 | 817 | "description": "Detects an unusual host name for a user.",
|
797 | 818 | "analysis_config": {
|
|
0 commit comments