Skip to content

[Security Rules] Update security rules package to v9.5.6-beta.1 - #21288

Merged
shashank-elastic merged 2 commits into
mainfrom
detection-rules/9.5.6-beta.1-9a63e3c91
Sep 16, 2026
Merged

shashank-elastic merged 2 commits into
mainfrom
detection-rules/9.5.6-beta.1-9a63e3c91

Conversation

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

What does this PR do?

Update the Security Rules package to version 9.5.6-beta.1.
Autogenerated from commit https://github.com/elastic/detection-rules/tree/9a63e3c9147a1a0a8c3ed23865cb6fbbcc334cb9

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • If I'm introducing a new feature, I have modified the Kibana version constraint in my package's manifest.yml file to point to the latest Elastic stack release (e.g. ^7.13.0).

Author's Checklist

  • Install the most recently release security rules in the Detection Engine
  • Install the package
  • Confirm the update is available in Kibana. Click "Update X rules" or "Install X rules"
  • Look at the changes made after the install and confirm they are consistent

How to test this PR locally

  • Perform the above checklist, and use package-storage to build EPR from source

Related issues

None

Screenshots

None

@github-actions

Copy link
Copy Markdown
Contributor

✅ Elastic Docs Style Checker (Vale)

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale.

@shashank-elastic shashank-elastic added enhancement New feature or request Integration:security_detection_engine Prebuilt Security Detection Rules labels Sep 16, 2026
@shashank-elastic
shashank-elastic marked this pull request as ready for review September 16, 2026 06:10
@shashank-elastic
shashank-elastic requested a review from a team as a code owner September 16, 2026 06:10
Copilot AI lite review requested due to automatic review settings September 16, 2026 06:10
@shashank-elastic
shashank-elastic enabled auto-merge (squash) September 16, 2026 06:10
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor Author

✅ All changelog entries have the correct PR link.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved moderate detection-rule correctness findings remain.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Updates the Security Detection Engine package to 9.5.6-beta.1 with synchronized generated detection rules.

Changes:

  • Bumps the package version and adds the release changelog.
  • Adds, removes, and refreshes generated security-rule definitions.
  • Updates integration field metadata.

Final review comments leave five moderate findings and one nit unresolved.

File summaries
File Summary
packages/security_detection_engine/manifest.yml Package metadata and version update.
packages/security_detection_engine/kibana/security_rule/fc552f49-8f1c-409b-90f8-6f5b9869b6c4_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/f8a31c62-0d4e-4b9a-b7e1-6c2a9d4e8f10_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/f1a2b3c4-d5e6-4789-a012-3456789abc01_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/eabaf807-e710-4f0f-8943-8d1b436d834a_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/e71ae602-bf44-4834-a4ea-b5c87047d426_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/e3f4a5b6-c7d8-9012-cdef-34567890abcd_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/e12c0318-99b1-44f2-830c-3a38a43207ca_213.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/dfe3f626-4224-417e-aff1-8ef9a72c3191_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/d7e62693-aab9-4f66-a21a-3d79ecdd603d_111.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/cf53f532-9cc9-445a-9ae7-fced307ec53c_108.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/c9d4e8f1-2a3b-4c5d-8e9f-0a1b2c3d4e5f_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/c5ce48a6-7f57-4ee8-9313-3d0024caee10_313.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/b8654454-2757-41b4-ae1a-69b3be704c28_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/b2c3d4e5-f6a7-4890-b1c2-d3e4f5a60789_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/ad8ca41c-8e3d-49cd-b130-42af09d1eb42_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/a9cb3641-ff4b-4cdc-a063-b4b8d02a67c7_110.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/a8e7d6c5-b4a3-2918-0f9e-8d7c6b5a4032_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/a44bcb58-5109-4870-a7c6-11f5fe7dd4b1_3.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/9edd000e-cbd1-4d6a-be72-2197b5625a05_6.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/9bed06f5-0c32-488a-9353-d565fc9d1573_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/9395fd2c-9947-4472-86ef-4aceb2f7e872_212.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/8d05971b-5858-4b72-b09a-17e3cee0af54_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/8c6f8cca-f730-4cdd-93a7-d65f087a4116_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/884e87cc-c67b-4c90-a4ed-e1e24a940c82_8.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/8623535c-1e17-44e1-aa97-7a0699c3037d_211.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/7f7a0ee1-7b6f-466a-85b4-110fb105f5e2_3.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/7e1b0654-b6c0-4b1b-ab47-75588533083c_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/7d091a76-0737-11ef-8469-f661ea17fbcc_8.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/6a309864-fc3f-11ee-b8cc-f661ea17fbce_6.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/696015ef-718e-40ff-ac4a-cc2ba88dbeeb_15.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/68c5c9d1-38e5-48bb-b1b2-8b5951d39738_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/6756ee27-9152-479b-9b73-54b5bbda301c_8.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/63c056a0-339a-11ed-a261-0242ac120002_10.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/5930658c-2107-4afc-91af-e0e55b7f7184_211.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/523116c0-d89d-4d7c-82c2-39e6845a78ef_211.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/4a4e23cf-78a2-449c-bac3-701924c269d3_109.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/4159bec9-76ad-4cdc-a797-4a8572073bbe_1.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/3e002465-876f-4f04-b016-84ef48ce7e5d_214.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/32f95776-6498-4f3c-a90c-d4f6083e3901_105.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/32144184-7bfa-4541-9c3f-b65f16d24df9_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/2f95540c-923e-4f57-9dae-de30169c68b9_6.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/29ef5686-9b93-433e-91b5-683911094698_4.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/263481c8-1e9b-492e-912d-d1760707f810_111.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/1251b98a-ff45-11ee-89a1-f661ea17fbce_2.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/10445cf0-0748-11ef-ba75-f661ea17fbcc_3.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/0d160033-fab7-4e72-85a3-3a9d80c8bff7_10.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/0415258b-a7b2-48a6-891a-3367cd9d4d31_6.json Generated detection-rule artifact update.
packages/security_detection_engine/kibana/security_rule/02ea4563-ec10-4974-b7de-12e65aa4f9b3_110.json Generated detection-rule artifact update.
packages/security_detection_engine/changelog.yml Release changelog entry.
Review details

Suppressed comments (1)

packages/security_detection_engine/kibana/security_rule/3c82bf84-5941-495b-ac41-0302f28e1a90_4.json:14

  • This sequence matches every allowed Role/ClusterRole create/update/patch; it never inspects kubernetes.audit.requestObject.rules.resources or kubernetes.audit.requestObject.rules.verb for wildcard or escalation permissions. Consequently ordinary least-privilege RBAC edits followed by a workload change can alert, while the high-risk permission behavior described by this rule is not actually detected. Add predicates for the high-risk rule entries, or revise the description and triage if broad mutation correlation is intended.
  • Files reviewed: 78/178 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

"required_fields": [
{
"ecs": false,
"name": "aws.cloudtrail.flattened.request_parameters.VersioningConfiguration.MfaDelete",
"azure.resource.id"
],
"note": "## Triage and analysis\n\n### Investigating Azure Storage Anonymous Blob Access to Unusual Resource\n\nStorageRead platform logs record `AuthenticationType` as Anonymous when no SAS, OAuth, or account key is presented.\nA first-seen `azure.resource.id` (typically the blob service\n`/subscriptions/.../storageAccounts/<account>/blobServices/default`) means this resource has not had anonymous Get or\nList traffic in the history window.\n\nWireServer SAS-replay chains often start with an anonymous GetBlob (HTTP 409/403) against the same object, then a\nSAS 200. This rule does not require guest-agent path strings; those lab container names are not production\nobservables.\n\n`source.ip` is often empty. Use `source.address` (`ip:port`).\n\n### Possible investigation steps\n\n- Review `event.action`, `azure.platformlogs.statusCode`, and `azure.platformlogs.uri`.\n- HTTP 200 with Anonymous means the container or blob is publicly readable. HTTP 409/403 is a probe.\n- Identify the account from `azure.resource.id` / `azure.resource.name` and check whether public access is intended.\n- Search for SAS-authenticated GetBlob to the same account from the same source shortly after.\n- If the URI contains `/$system/` or `md-hdd-`, correlate with WireServer access on VMs in the subscription.\n\n### False positive analysis\n\n- Public blob websites and CDN origins. Exclude the `azure.resource.id` for approved public accounts.\n- New accounts that enable StorageRead for the first time will alert on the first scanner hit.\n\n### Response and remediation\n\n- Disable anonymous public access on accounts that should be private.\n- If a follow-on SAS read exists, revoke that SAS and review how the URL was obtained.\n- Keep StorageRead diagnostic logs enabled on storage accounts of interest.\n",
"query": "data_stream.dataset: azure.platformlogs and\n azure.platformlogs.identity.type: Anonymous and\n event.action: (\n GetBlob or GetBlobMetadata or GetBlobProperties or GetBlockList or\n GetPageRanges or QueryBlobContents or ListBlobs or\n GetContainerProperties or GetContainerMetadata or GetContainerAcl\n )\n",
@github-actions

This comment has been minimized.

@github-actions github-actions Bot mentioned this pull request Sep 16, 2026
@github-actions

Copy link
Copy Markdown
Contributor

TL;DR

The current failing Buildkite OOM step is a test/runtime failure in Kibana FTR (TypeError: Cannot read properties of undefined (reading 'init-prebuilt-rules')), not the earlier 502 error reported in a prior run. Immediate action: re-run the same OOM step with API response logging enabled for prebuilt-rules install to capture the missing object shape and pinpoint the offending rule payload.

Remediation

  • Re-run :test_tube: Run FTR OOM tests for commit 2170c76e4b53406217a43c31c3e49f107dfbd17c; this run should collect/print the install API response body right before the assertion at install_prebuilt_rules.ts:99.
  • If the response contains per-rule errors (instead of expected summary stats), identify the failing rule asset from this PR (packages/security_detection_engine/kibana/security_rule/*.json) and regenerate/fix that rule payload before re-running OOM tests.
Investigation details

Root Cause

The failing step crashes in the test itself while dereferencing init-prebuilt-rules from an undefined object in Kibana FTR:

  • x-pack/solutions/security/test/security_solution_api_integration/test_suites/detections_response/rules_management/prebuilt_rules/oom_testing/install_prebuilt_rules/install_prebuilt_rules.ts:99

This indicates the expected install summary/stats object was not present in the response shape consumed by the test.

The PR modifies security_detection_engine assets (changelog plus many kibana/security_rule/*.json files), so a malformed or incompatible updated rule payload is a plausible trigger. The available log does not include the response body, so the exact offending rule cannot be identified from this run alone.

Evidence

TypeError: Cannot read properties of undefined (reading 'init-prebuilt-rules')
at .../prebuilt_rules/oom_testing/install_prebuilt_rules/install_prebuilt_rules.ts:99:32

Verification

  • Reviewed pre-fetched Buildkite failure summary and full failing log at:
    • /tmp/gh-aw/buildkite-failures.txt
    • /tmp/gh-aw/buildkite-logs/appex-qa-stateful-security-prebuilt-rules-ftr-oom-testing-test_tube-run-ftr-oom-tests-package-version-956-beta1-epr-ht.txt
  • Reviewed PR metadata and changed-file list for #21288 via GitHub MCP (pull_request_read).

Follow-up

If re-run still fails, add temporary logging in the Kibana OOM test around the install response object (same line region) so the failure reports concrete response/error payload instead of an undefined-property exception.


What is this? | From workflow: PR Buildkite Detective

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

@shashank-elastic
shashank-elastic merged commit 08c10d1 into main Sep 16, 2026
10 checks passed
@shashank-elastic
shashank-elastic deleted the detection-rules/9.5.6-beta.1-9a63e3c91 branch September 16, 2026 12:41
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor Author

Package security_detection_engine - 9.5.6-beta.1 containing this change is available at https://epr.elastic.co/package/security_detection_engine/9.5.6-beta.1/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:security_detection_engine Prebuilt Security Detection Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants