Repository navigation
[Security Rules] Update security rules package to v9.5.6-beta.1 - #21288
Conversation
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
|
✅ All changelog entries have the correct PR link. |
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved moderate detection-rule correctness findings remain.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates the Security Detection Engine package to 9.5.6-beta.1 with synchronized generated detection rules.
Changes:
- Bumps the package version and adds the release changelog.
- Adds, removes, and refreshes generated security-rule definitions.
- Updates integration field metadata.
Final review comments leave five moderate findings and one nit unresolved.
File summaries
| File | Summary |
|---|---|
packages/security_detection_engine/manifest.yml |
Package metadata and version update. |
packages/security_detection_engine/kibana/security_rule/fc552f49-8f1c-409b-90f8-6f5b9869b6c4_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/f8a31c62-0d4e-4b9a-b7e1-6c2a9d4e8f10_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/f1a2b3c4-d5e6-4789-a012-3456789abc01_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/eabaf807-e710-4f0f-8943-8d1b436d834a_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/e71ae602-bf44-4834-a4ea-b5c87047d426_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/e3f4a5b6-c7d8-9012-cdef-34567890abcd_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/e12c0318-99b1-44f2-830c-3a38a43207ca_213.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/dfe3f626-4224-417e-aff1-8ef9a72c3191_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/d7e62693-aab9-4f66-a21a-3d79ecdd603d_111.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/cf53f532-9cc9-445a-9ae7-fced307ec53c_108.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/c9d4e8f1-2a3b-4c5d-8e9f-0a1b2c3d4e5f_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/c8a2d4f6-1b3e-4a7c-9d5f-8e0b2c6a4d1e_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/c5ce48a6-7f57-4ee8-9313-3d0024caee10_313.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/b8654454-2757-41b4-ae1a-69b3be704c28_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/b2c3d4e5-f6a7-4890-b1c2-d3e4f5a60789_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/ad8ca41c-8e3d-49cd-b130-42af09d1eb42_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/a9cb3641-ff4b-4cdc-a063-b4b8d02a67c7_110.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/a8e7d6c5-b4a3-2918-0f9e-8d7c6b5a4032_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/a44bcb58-5109-4870-a7c6-11f5fe7dd4b1_3.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/9edd000e-cbd1-4d6a-be72-2197b5625a05_6.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/9bed06f5-0c32-488a-9353-d565fc9d1573_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/9395fd2c-9947-4472-86ef-4aceb2f7e872_212.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/8d05971b-5858-4b72-b09a-17e3cee0af54_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/8c6f8cca-f730-4cdd-93a7-d65f087a4116_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/884e87cc-c67b-4c90-a4ed-e1e24a940c82_8.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/8623535c-1e17-44e1-aa97-7a0699c3037d_211.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/7f7a0ee1-7b6f-466a-85b4-110fb105f5e2_3.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/7e1b0654-b6c0-4b1b-ab47-75588533083c_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/7d091a76-0737-11ef-8469-f661ea17fbcc_8.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/6a309864-fc3f-11ee-b8cc-f661ea17fbce_6.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/696015ef-718e-40ff-ac4a-cc2ba88dbeeb_15.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/68c5c9d1-38e5-48bb-b1b2-8b5951d39738_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/6756ee27-9152-479b-9b73-54b5bbda301c_8.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/63c056a0-339a-11ed-a261-0242ac120002_10.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/5930658c-2107-4afc-91af-e0e55b7f7184_211.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/523116c0-d89d-4d7c-82c2-39e6845a78ef_211.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/4a4e23cf-78a2-449c-bac3-701924c269d3_109.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/4159bec9-76ad-4cdc-a797-4a8572073bbe_1.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/3e002465-876f-4f04-b016-84ef48ce7e5d_214.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/32f95776-6498-4f3c-a90c-d4f6083e3901_105.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/32144184-7bfa-4541-9c3f-b65f16d24df9_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/2f95540c-923e-4f57-9dae-de30169c68b9_6.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/29ef5686-9b93-433e-91b5-683911094698_4.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/263481c8-1e9b-492e-912d-d1760707f810_111.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/1251b98a-ff45-11ee-89a1-f661ea17fbce_2.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/10445cf0-0748-11ef-ba75-f661ea17fbcc_3.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/0d160033-fab7-4e72-85a3-3a9d80c8bff7_10.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/0415258b-a7b2-48a6-891a-3367cd9d4d31_6.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/kibana/security_rule/02ea4563-ec10-4974-b7de-12e65aa4f9b3_110.json |
Generated detection-rule artifact update. |
packages/security_detection_engine/changelog.yml |
Release changelog entry. |
Review details
Suppressed comments (1)
packages/security_detection_engine/kibana/security_rule/3c82bf84-5941-495b-ac41-0302f28e1a90_4.json:14
- This sequence matches every allowed Role/ClusterRole create/update/patch; it never inspects
kubernetes.audit.requestObject.rules.resourcesorkubernetes.audit.requestObject.rules.verbfor wildcard or escalation permissions. Consequently ordinary least-privilege RBAC edits followed by a workload change can alert, while the high-risk permission behavior described by this rule is not actually detected. Add predicates for the high-risk rule entries, or revise the description and triage if broad mutation correlation is intended.
- Files reviewed: 78/178 changed files
- Comments generated: 2
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| "required_fields": [ | ||
| { | ||
| "ecs": false, | ||
| "name": "aws.cloudtrail.flattened.request_parameters.VersioningConfiguration.MfaDelete", |
| "azure.resource.id" | ||
| ], | ||
| "note": "## Triage and analysis\n\n### Investigating Azure Storage Anonymous Blob Access to Unusual Resource\n\nStorageRead platform logs record `AuthenticationType` as Anonymous when no SAS, OAuth, or account key is presented.\nA first-seen `azure.resource.id` (typically the blob service\n`/subscriptions/.../storageAccounts/<account>/blobServices/default`) means this resource has not had anonymous Get or\nList traffic in the history window.\n\nWireServer SAS-replay chains often start with an anonymous GetBlob (HTTP 409/403) against the same object, then a\nSAS 200. This rule does not require guest-agent path strings; those lab container names are not production\nobservables.\n\n`source.ip` is often empty. Use `source.address` (`ip:port`).\n\n### Possible investigation steps\n\n- Review `event.action`, `azure.platformlogs.statusCode`, and `azure.platformlogs.uri`.\n- HTTP 200 with Anonymous means the container or blob is publicly readable. HTTP 409/403 is a probe.\n- Identify the account from `azure.resource.id` / `azure.resource.name` and check whether public access is intended.\n- Search for SAS-authenticated GetBlob to the same account from the same source shortly after.\n- If the URI contains `/$system/` or `md-hdd-`, correlate with WireServer access on VMs in the subscription.\n\n### False positive analysis\n\n- Public blob websites and CDN origins. Exclude the `azure.resource.id` for approved public accounts.\n- New accounts that enable StorageRead for the first time will alert on the first scanner hit.\n\n### Response and remediation\n\n- Disable anonymous public access on accounts that should be private.\n- If a follow-on SAS read exists, revoke that SAS and review how the URL was obtained.\n- Keep StorageRead diagnostic logs enabled on storage accounts of interest.\n", | ||
| "query": "data_stream.dataset: azure.platformlogs and\n azure.platformlogs.identity.type: Anonymous and\n event.action: (\n GetBlob or GetBlobMetadata or GetBlobProperties or GetBlockList or\n GetPageRanges or QueryBlobContents or ListBlobs or\n GetContainerProperties or GetContainerMetadata or GetContainerAcl\n )\n", |
This comment has been minimized.
This comment has been minimized.
TL;DRThe current failing Buildkite OOM step is a test/runtime failure in Kibana FTR ( Remediation
Investigation detailsRoot CauseThe failing step crashes in the test itself while dereferencing
This indicates the expected install summary/stats object was not present in the response shape consumed by the test. The PR modifies Evidence
Verification
Follow-upIf re-run still fails, add temporary logging in the Kibana OOM test around the install response object (same line region) so the failure reports concrete response/error payload instead of an undefined-property exception. What is this? | From workflow: PR Buildkite Detective Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not. |
|
Package security_detection_engine - 9.5.6-beta.1 containing this change is available at https://epr.elastic.co/package/security_detection_engine/9.5.6-beta.1/ |
What does this PR do?
Update the Security Rules package to version 9.5.6-beta.1.
Autogenerated from commit https://github.com/elastic/detection-rules/tree/9a63e3c9147a1a0a8c3ed23865cb6fbbcc334cb9
Checklist
I have verified that all data streams collect metrics or logs.changelog.ymlfile.manifest.ymlfile to point to the latest Elastic stack release (e.g.^7.13.0).Author's Checklist
How to test this PR locally
package-storageto build EPR from sourceRelated issues
None
Screenshots
None