Terrance DeJesus

Results 24 issues of Terrance DeJesus

# Pull Request *Issue link(s)*: * https://github.com/elastic/ia-trade-team/issues/585 ## Summary - What I changed Adds detection coverage for `AWS STS Temporary IAM Session Token Used from Multiple Addresses`. Identified via ByBit/SafeWallet...

Integration: AWS
Domain: Cloud
Rule: New
backport: auto

# Pull Request *Issue link(s)*: * https://github.com/elastic/ia-trade-team/issues/585 ## Summary - What I changed Adds coverage for static JS file uploads to AWS S3 buckets. This is a signal for potential...

Integration: AWS
Domain: Cloud
Rule: New
backport: auto

# Pull Request *Issue link(s)*: * https://github.com/elastic/ia-trade-team/issues/585 ## Summary - What I changed Adds detection coverage for AWS CLI or SDK (Boto3) usage with Kali Linux fingerprint as well. Identifies...

Integration: AWS
Domain: Cloud
Rule: New
backport: auto

# Pull Request *Issue link(s)*: * https://github.com/elastic/ia-trade-team/issues/585 ## Summary - What I changed Adds detection coverage for AWS MFA device registration attempts with temporary credentials (user session tokens). Identifies attempts...

Integration: AWS
Domain: Cloud
Rule: New
backport: auto

# Pull Request *Issue link(s)*: * https://github.com/elastic/ia-trade-team/issues/585 ## Summary - What I changed Adds detection coverage for `AWS IAM or STS API Calls via Temporary Session Tokens`. Detects use of...

Integration: AWS
Domain: Cloud
Rule: New
backport: auto

**Is your feature request related to a problem? Please describe.** This feature request is not related to a problem, it is more of a small enhancement to current capabilities. Within...

enhancement
python
backlog

## Related * https://github.com/elastic/detection-rules/pull/3316 ## Summary As discussed and shown in #3316, the use of `*` wildcards in certain field types fail semantic validation via the KQL parser library, but...

bug
kql
backlog

### Repository Feature Core Repo - (rule management, validation, testing, lib, cicd, etc.) ### Problem Description At the moment, when using ES|QL for writing detection rule queries, often we use...

enhancement
backlog
Team: TRADE

## Summary Google released from research into Google Workspace being used for C2, specifically involving Drive where file types are Sheets, Golang and PE. Reference: https://services.google.com/fh/files/blogs/gcat_threathorizons_full_apr2023.pdf Tool: https://github.com/looCiprian/GC2-sheet With the...

Rule: New
Integration: Google Workspace
backlog
v8.8.0

### Description Review detection coverage for C2 via Google Sheets from recent "Voldemort" campaign. ### Target Ruleset windows ### Target Rule Type Event Correlation (EQL) ### Tested ECS Version _No...

Rule: New
OS: Windows
Domain: Endpoint
backlog
Integration: Endpoint
Team: TRADE
Domain: SaaS