File tree Expand file tree Collapse file tree
.cypress/fixtures/integration_tests/rule Expand file tree Collapse file tree Original file line number Diff line number Diff line change 11{
2- "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f325" ,
3- "category" : " dns" ,
4- "title" : " Cypress DNS Rule" ,
5- "description" : " Detects DNS name as QWE" ,
6- "status" : " experimental" ,
7- "author" : " Cypress Tests" ,
8- "references" : [
9- {
10- "value" : " "
11- }
12- ],
13- "tags" : [
14- {
15- "value" : " dns.high"
16- }
17- ],
18- "log_source" : " " ,
19- "detection" : " selection:\n dns-question-name:\n - QuestionName\n condition: selection" ,
20- "level" : " high" ,
21- "false_positives" : [
22- {
23- "value" : " "
24- }
25- ]
2+ "rule" : {
3+ "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f325" ,
4+ "category" : " dns" ,
5+ "title" : " Cypress DNS Rule" ,
6+ "description" : " Detects DNS name as QWE" ,
7+ "status" : " experimental" ,
8+ "author" : " Cypress Tests" ,
9+ "references" : [
10+ {
11+ "value" : " "
12+ }
13+ ],
14+ "tags" : [
15+ {
16+ "value" : " dns.high"
17+ }
18+ ],
19+ "log_source" : " " ,
20+ "detection" : " selection:\n dns-question-name:\n - QuestionName\n condition: selection" ,
21+ "level" : " high" ,
22+ "false_positives" : [
23+ {
24+ "value" : " "
25+ }
26+ ]
27+ }
2628}
Original file line number Diff line number Diff line change 11{
2- "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f325" ,
3- "category" : " dns" ,
4- "title" : " Cypress DNS Type Rule" ,
5- "description" : " Detects DNS type as QWE" ,
6- "status" : " experimental" ,
7- "author" : " Cypress Tests" ,
8- "references" : [
9- {
10- "value" : " "
11- }
12- ],
13- "tags" : [
14- {
15- "value" : " dns.high"
16- }
17- ],
18- "log_source" : " " ,
19- "detection" : " selection:\n dns-answers-type:\n - AnswerType\n condition: selection" ,
20- "level" : " high" ,
21- "false_positives" : [
22- {
23- "value" : " "
24- }
25- ]
2+ "rule" : {
3+ "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f325" ,
4+ "category" : " dns" ,
5+ "title" : " Cypress DNS Type Rule" ,
6+ "description" : " Detects DNS type as QWE" ,
7+ "status" : " experimental" ,
8+ "author" : " Cypress Tests" ,
9+ "references" : [
10+ {
11+ "value" : " "
12+ }
13+ ],
14+ "tags" : [
15+ {
16+ "value" : " dns.high"
17+ }
18+ ],
19+ "log_source" : " " ,
20+ "detection" : " selection:\n dns-answers-type:\n - AnswerType\n condition: selection" ,
21+ "level" : " high" ,
22+ "false_positives" : [
23+ {
24+ "value" : " "
25+ }
26+ ]
27+ }
2628}
Original file line number Diff line number Diff line change 11{
2- "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f326" ,
3- "category" : " network" ,
4- "title" : " Cypress Network Rule" ,
5- "description" : " Detects network changes" ,
6- "status" : " experimental" ,
7- "author" : " Cypress Tests" ,
8- "references" : [
9- {
10- "value" : " "
11- }
12- ],
13- "tags" : [
14- {
15- "value" : " network.high"
16- }
17- ],
18- "log_source" : " " ,
19- "detection" : " selection:\n keywords:\n - erase\n - delete\n - YXC\n condition: selection" ,
20- "level" : " high" ,
21- "false_positives" : [
22- {
23- "value" : " "
24- }
25- ]
2+ "rule" : {
3+ "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f326" ,
4+ "category" : " network" ,
5+ "title" : " Cypress Network Rule" ,
6+ "description" : " Detects network changes" ,
7+ "status" : " experimental" ,
8+ "author" : " Cypress Tests" ,
9+ "references" : [
10+ {
11+ "value" : " "
12+ }
13+ ],
14+ "tags" : [
15+ {
16+ "value" : " network.high"
17+ }
18+ ],
19+ "log_source" : " " ,
20+ "detection" : " selection:\n keywords:\n - erase\n - delete\n - YXC\n condition: selection" ,
21+ "level" : " high" ,
22+ "false_positives" : [
23+ {
24+ "value" : " "
25+ }
26+ ]
27+ }
2628}
Original file line number Diff line number Diff line change 11{
2- "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f123" ,
3- "category" : " windows" ,
4- "title" : " Cypress USB Rule" ,
5- "description" : " USB plugged-in rule" ,
6- "status" : " experimental" ,
7- "author" : " Cypress Tests" ,
8- "references" : [
9- {
10- "value" : " "
11- }
12- ],
13- "tags" : [
14- {
15- "value" : " windows.usb"
16- }
17- ],
18- "log_source" : " " ,
19- "detection" : " selection:\n winlog-event_id:\n - 2003\n - 2100\n - 2102\n condition: selection" ,
20- "level" : " high" ,
21- "false_positives" : [
22- {
23- "value" : " "
24- }
25- ]
2+ "rule" : {
3+ "id" : " 25b9c01c-350d-4b95-bed1-836d04a4f123" ,
4+ "category" : " windows" ,
5+ "title" : " Cypress USB Rule" ,
6+ "description" : " USB plugged-in rule" ,
7+ "status" : " experimental" ,
8+ "author" : " Cypress Tests" ,
9+ "references" : [
10+ {
11+ "value" : " "
12+ }
13+ ],
14+ "tags" : [
15+ {
16+ "value" : " windows.usb"
17+ }
18+ ],
19+ "log_source" : " " ,
20+ "detection" : " selection:\n winlog-event_id:\n - 2003\n - 2100\n - 2102\n condition: selection" ,
21+ "level" : " high" ,
22+ "false_positives" : [
23+ {
24+ "value" : " "
25+ }
26+ ]
27+ }
2628}
You can’t perform that action at this time.
0 commit comments