Skip to content

[FR] Batch One Network RTAs#34

Open
eric-forte-elastic wants to merge 26 commits into
mainfrom
batch_one_network_rtas
Open

[FR] Batch One Network RTAs#34
eric-forte-elastic wants to merge 26 commits into
mainfrom
batch_one_network_rtas

Conversation

@eric-forte-elastic

@eric-forte-elastic eric-forte-elastic commented Apr 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds a number of Linux network RTAs for the rules in elastic/detection-rules#5932. This will be left in draft until that PR merges.

Example detonation from running the RDP RTA twice

image

@eric-forte-elastic eric-forte-elastic self-assigned this Apr 29, 2026
@eric-forte-elastic eric-forte-elastic marked this pull request as ready for review May 4, 2026 15:28
@eric-forte-elastic eric-forte-elastic requested a review from a team as a code owner May 4, 2026 15:28
@eric-forte-elastic eric-forte-elastic changed the title WIP - [FR] Batch One Network RTAs [FR] Batch One Network RTAs May 4, 2026
@eric-forte-elastic

Copy link
Copy Markdown
Contributor Author

DHCP RTA Testing
image

@eric-forte-elastic

Copy link
Copy Markdown
Contributor Author

New RTA fires:
image

@eric-forte-elastic

Copy link
Copy Markdown
Contributor Author

Added RediShell RTA
image

@eric-forte-elastic

Copy link
Copy Markdown
Contributor Author

Redis Raider RTA
image

@eric-forte-elastic

Copy link
Copy Markdown
Contributor Author

Redis SSH key Injection
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant