The textproc/opensearch port
opensearch-3.4.0 – distributed and RESTful search engine (cvsweb github mirror)
Description
OpenSearch is a community-driven, open source search and analytics suite derived from the Apache 2.0 licensed Elasticsearch 7.10.2WWW: https://www.opensearch.org/
Readme
+-------------------------------------------------------------------------------
| Running ${PKGSTEM} on OpenBSD
+-------------------------------------------------------------------------------
Initial Node/Cluster Configuration
==================================
Configuration files are located in ${SYSCONFDIR}/opensearch
The security plugin is enabled by default and needs to be configured
before starting OpenSearch.
For demo/testing purposes, basic security configuration can be created
by running:
# doas -u _opensearch \
${TRUEPREFIX}/opensearch/plugins/opensearch-security/tools/install_demo_configuration.sh
Upstream documentation:
https://opensearch.org/docs/latest/security-plugin/configuration/index
By default, OpenSearch binds to a localhost addresses. Since OpenBSD does
not support IPv4 to IPv6 address mapping, either IPv4 or IPv6 can be
used, but not both of them (see JDK/JRE package README for more details.)
Thus by default OpenSearch will bind to 127.0.0.1 and will not be useful
for anything except testing.
After configuring network.host to non-default localhost address,
OpenSearch will assume it's in "production" mode and will enforce
the following bootstrap checks:
- maximum number of open file descriptors must be >= 65535 (see below)
- discovery.seed_hosts and cluster.initial_cluster_manager_nodes
must be configured in ${SYSCONFDIR}/opensearch/opensearch.yml
Upstream documentation:
https://opensearch.org/docs/latest/opensearch/configuration/#configuration-file
Resource Limits: File Descriptors
=================================
A sample login class has been provided in /etc/login.conf.d/elasticsearch.
To raise the default system limit, adjust kern.maxfiles:
# sysctl kern.maxfiles=65535
# echo kern.maxfiles=65535 >> /etc/sysctl.conf
For a busy OpenSearch node with lots of indexes, maxfiles/openfiles limits
should be increased even more, e.g. 131070.
You can query the number of open file descriptors along with the maximum
allowed by running
$ ftp -S dont -o - 'https://admin:admin@localhost:9200/_nodes/stats/process?pretty'
and searching for "open_file_descriptors" and "max_file_descriptors"
values.
Resource Limits: Maximum Number of File Locks
=============================================
If you are getting "java.io.IOException: No locks available" errors,
increase kern.maxlocksperuid over the default of 1024:
# sysctl kern.maxlocksperuid=2048
# echo kern.maxlocksperuid=2048 >> /etc/sysctl.conf
OpenSearch Plugins Management
=============================
Installing plugins may involve running Java code which can download and
execute arbitrary code from the Internet. To avoid running these tasks
as root, use doas(1):
# doas -u _opensearch \
${TRUEPREFIX}/opensearch/bin/opensearch-plugin install ...
Migrate from ElasticSearch
==========================
There are different approaches to migrate from ElasticSearch to
OpenSearch. Upstream documents three migration strategies:
https://opensearch.org/docs/latest/upgrade-to/index
Regardless of the approach choosen, to safeguard against data loss, is
recommend to take a snapshot of all indices prior to any migration.
Maintainer
Omar Polo, Pavel Korovin
Only for arches
aarch64 amd64 i386
Categories
Build dependencies
Run dependencies
Files
- /etc/login.conf.d/opensearch
- /etc/opensearch/
- /etc/opensearch/fips_java.security
- /etc/opensearch/jvm.options
- /etc/opensearch/jvm.options.d/
- /etc/opensearch/log4j2.properties
- /etc/opensearch/opensearch-notifications-core/
- /etc/opensearch/opensearch-notifications-core/notifications-core.yml
- /etc/opensearch/opensearch-notifications/
- /etc/opensearch/opensearch-notifications/notifications.yml
- /etc/opensearch/opensearch-observability/
- /etc/opensearch/opensearch-observability/observability.yml
- /etc/opensearch/opensearch-reports-scheduler/
- /etc/opensearch/opensearch-reports-scheduler/reports-scheduler.yml
- /etc/opensearch/opensearch-security/
- /etc/opensearch/opensearch-security/action_groups.yml
- /etc/opensearch/opensearch-security/allowlist.yml
- /etc/opensearch/opensearch-security/audit.yml
- /etc/opensearch/opensearch-security/config.yml
- /etc/opensearch/opensearch-security/internal_users.yml
- /etc/opensearch/opensearch-security/nodes_dn.yml
- /etc/opensearch/opensearch-security/opensearch.yml.example
- /etc/opensearch/opensearch-security/roles.yml
- /etc/opensearch/opensearch-security/roles_mapping.yml
- /etc/opensearch/opensearch-security/tenants.yml
- /etc/opensearch/opensearch.yml
- /etc/rc.d/opensearch
- /usr/local/opensearch/
- /usr/local/opensearch/agent/
- /usr/local/opensearch/agent/byte-buddy-1.17.7.jar
- /usr/local/opensearch/agent/opensearch-agent-bootstrap-3.4.0.jar
- /usr/local/opensearch/agent/opensearch-agent.jar
- /usr/local/opensearch/bin/
- /usr/local/opensearch/bin/opensearch
- /usr/local/opensearch/bin/opensearch-cli
- /usr/local/opensearch/bin/opensearch-env
- /usr/local/opensearch/bin/opensearch-env-from-file
- /usr/local/opensearch/bin/opensearch-fips-demo-installer
- /usr/local/opensearch/bin/opensearch-keystore
- /usr/local/opensearch/bin/opensearch-node
- /usr/local/opensearch/bin/opensearch-performance-analyzer/
- /usr/local/opensearch/bin/opensearch-performance-analyzer/performance-analyzer-agent-cli
- /usr/local/opensearch/bin/opensearch-plugin
- /usr/local/opensearch/bin/opensearch-shard
- /usr/local/opensearch/lib/
- /usr/local/opensearch/lib/HdrHistogram-2.2.2.jar
- /usr/local/opensearch/lib/RoaringBitmap-1.3.0.jar
- /usr/local/opensearch/lib/jackson-core-2.18.2.jar
- /usr/local/opensearch/lib/jackson-dataformat-cbor-2.18.2.jar
- /usr/local/opensearch/lib/jackson-dataformat-smile-2.18.2.jar
- /usr/local/opensearch/lib/jackson-dataformat-yaml-2.18.2.jar
- /usr/local/opensearch/lib/jakarta.annotation-api-1.3.5.jar
- /usr/local/opensearch/lib/java-version-checker-3.4.0.jar
- /usr/local/opensearch/lib/joda-time-2.12.7.jar
- /usr/local/opensearch/lib/jopt-simple-5.0.4.jar
- /usr/local/opensearch/lib/jts-core-1.15.0.jar
- /usr/local/opensearch/lib/jzlib-1.1.3.jar
- /usr/local/opensearch/lib/log4j-api-2.21.0.jar
- /usr/local/opensearch/lib/log4j-core-2.21.0.jar
- /usr/local/opensearch/lib/log4j-jul-2.21.0.jar
- /usr/local/opensearch/lib/lucene-analysis-common-10.3.2.jar
- /usr/local/opensearch/lib/lucene-backward-codecs-10.3.2.jar
- /usr/local/opensearch/lib/lucene-core-10.3.2.jar
- /usr/local/opensearch/lib/lucene-grouping-10.3.2.jar
- /usr/local/opensearch/lib/lucene-highlighter-10.3.2.jar
- /usr/local/opensearch/lib/lucene-join-10.3.2.jar
- /usr/local/opensearch/lib/lucene-memory-10.3.2.jar
- /usr/local/opensearch/lib/lucene-misc-10.3.2.jar
- /usr/local/opensearch/lib/lucene-queries-10.3.2.jar
- /usr/local/opensearch/lib/lucene-queryparser-10.3.2.jar
- /usr/local/opensearch/lib/lucene-sandbox-10.3.2.jar
- /usr/local/opensearch/lib/lucene-spatial-extras-10.3.2.jar
- /usr/local/opensearch/lib/lucene-spatial3d-10.3.2.jar
- /usr/local/opensearch/lib/lucene-suggest-10.3.2.jar
- /usr/local/opensearch/lib/opensearch-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-agent-policy-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-cli-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-common-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-compress-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-core-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-geo-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-launchers-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-plugin-classloader-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-secure-sm-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-task-commons-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-telemetry-3.4.0.jar
- /usr/local/opensearch/lib/opensearch-x-content-3.4.0.jar
- /usr/local/opensearch/lib/protobuf-java-3.25.8.jar
- /usr/local/opensearch/lib/reactive-streams-1.0.4.jar
- /usr/local/opensearch/lib/reactor-core-3.8.0.jar
- /usr/local/opensearch/lib/snakeyaml-2.1.jar
- /usr/local/opensearch/lib/spatial4j-0.7.jar
- /usr/local/opensearch/lib/t-digest-3.3.jar
- /usr/local/opensearch/lib/tools/
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/HdrHistogram-2.2.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/RoaringBitmap-1.3.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/bc-fips-2.1.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/fips-demo-installer-cli-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jackson-core-2.18.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jackson-dataformat-cbor-2.18.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jackson-dataformat-smile-2.18.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jackson-dataformat-yaml-2.18.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jakarta.annotation-api-1.3.5.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/java-version-checker-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jna-5.16.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/joda-time-2.12.7.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jopt-simple-5.0.4.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jts-core-1.15.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/jzlib-1.1.3.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/log4j-api-2.21.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/log4j-core-2.21.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/log4j-jul-2.21.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-analysis-common-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-backward-codecs-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-core-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-grouping-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-highlighter-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-join-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-memory-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-misc-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-queries-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-queryparser-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-sandbox-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-spatial-extras-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-spatial3d-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/lucene-suggest-10.3.2.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-agent-policy-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-cli-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-common-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-compress-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-core-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-geo-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-secure-sm-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-task-commons-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-telemetry-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/opensearch-x-content-3.4.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/picocli-4.7.7.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/protobuf-java-3.25.8.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/reactive-streams-1.0.4.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/reactor-core-3.8.0.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/snakeyaml-2.1.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/spatial4j-0.7.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/t-digest-3.3.jar
- /usr/local/opensearch/lib/tools/fips-demo-installer-cli/zstd-jni-1.5.6-1.jar
- /usr/local/opensearch/lib/tools/keystore-cli/
- /usr/local/opensearch/lib/tools/keystore-cli/keystore-cli-3.4.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/
- /usr/local/opensearch/lib/tools/plugin-cli/bc-fips-2.1.2.jar
- /usr/local/opensearch/lib/tools/plugin-cli/bcpg-fips-2.1.11.jar
- /usr/local/opensearch/lib/tools/plugin-cli/commons-codec-1.18.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/commons-compress-1.28.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/commons-io-2.16.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/commons-lang3-3.18.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/opensearch-agent-policy-3.4.0.jar
- /usr/local/opensearch/lib/tools/plugin-cli/opensearch-plugin-cli-3.4.0.jar
- /usr/local/opensearch/lib/zstd-jni-1.5.6-1.jar
- /usr/local/opensearch/manifest.yml
- /usr/local/opensearch/modules/
- /usr/local/opensearch/modules/aggs-matrix-stats/
- /usr/local/opensearch/modules/aggs-matrix-stats/aggs-matrix-stats-client-3.4.0.jar
- /usr/local/opensearch/modules/aggs-matrix-stats/plugin-descriptor.properties
- /usr/local/opensearch/modules/analysis-common/
- /usr/local/opensearch/modules/analysis-common/analysis-common-3.4.0.jar
- /usr/local/opensearch/modules/analysis-common/plugin-descriptor.properties
- /usr/local/opensearch/modules/cache-common/
- /usr/local/opensearch/modules/cache-common/cache-common-3.4.0.jar
- /usr/local/opensearch/modules/cache-common/plugin-descriptor.properties
- /usr/local/opensearch/modules/cache-common/plugin-security.policy
- /usr/local/opensearch/modules/geo/
- /usr/local/opensearch/modules/geo/geo-3.4.0.jar
- /usr/local/opensearch/modules/geo/plugin-descriptor.properties
- /usr/local/opensearch/modules/ingest-common/
- /usr/local/opensearch/modules/ingest-common/ingest-common-3.4.0.jar
- /usr/local/opensearch/modules/ingest-common/jcodings-1.0.63.jar
- /usr/local/opensearch/modules/ingest-common/joni-2.2.6.jar
- /usr/local/opensearch/modules/ingest-common/opensearch-dissect-3.4.0.jar
- /usr/local/opensearch/modules/ingest-common/opensearch-grok-3.4.0.jar
- /usr/local/opensearch/modules/ingest-common/plugin-descriptor.properties
- /usr/local/opensearch/modules/ingest-geoip/
- /usr/local/opensearch/modules/ingest-geoip/GeoLite2-ASN.mmdb
- /usr/local/opensearch/modules/ingest-geoip/GeoLite2-City.mmdb
- /usr/local/opensearch/modules/ingest-geoip/GeoLite2-Country.mmdb
- /usr/local/opensearch/modules/ingest-geoip/geoip2-4.4.0.jar
- /usr/local/opensearch/modules/ingest-geoip/ingest-geoip-3.4.0.jar
- /usr/local/opensearch/modules/ingest-geoip/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/modules/ingest-geoip/jackson-databind-2.18.2.jar
- /usr/local/opensearch/modules/ingest-geoip/jackson-datatype-jsr310-2.18.2.jar
- /usr/local/opensearch/modules/ingest-geoip/maxmind-db-3.2.0.jar
- /usr/local/opensearch/modules/ingest-geoip/plugin-descriptor.properties
- /usr/local/opensearch/modules/ingest-geoip/plugin-security.policy
- /usr/local/opensearch/modules/ingest-user-agent/
- /usr/local/opensearch/modules/ingest-user-agent/ingest-user-agent-3.4.0.jar
- /usr/local/opensearch/modules/ingest-user-agent/plugin-descriptor.properties
- /usr/local/opensearch/modules/lang-expression/
- /usr/local/opensearch/modules/lang-expression/antlr4-runtime-4.13.1.jar
- /usr/local/opensearch/modules/lang-expression/asm-9.7.jar
- /usr/local/opensearch/modules/lang-expression/asm-commons-9.7.jar
- /usr/local/opensearch/modules/lang-expression/asm-tree-9.7.jar
- /usr/local/opensearch/modules/lang-expression/lang-expression-3.4.0.jar
- /usr/local/opensearch/modules/lang-expression/lucene-expressions-10.3.2.jar
- /usr/local/opensearch/modules/lang-expression/plugin-descriptor.properties
- /usr/local/opensearch/modules/lang-expression/plugin-security.policy
- /usr/local/opensearch/modules/lang-mustache/
- /usr/local/opensearch/modules/lang-mustache/compiler-0.9.14.jar
- /usr/local/opensearch/modules/lang-mustache/lang-mustache-client-3.4.0.jar
- /usr/local/opensearch/modules/lang-mustache/plugin-descriptor.properties
- /usr/local/opensearch/modules/lang-mustache/plugin-security.policy
- /usr/local/opensearch/modules/lang-painless/
- /usr/local/opensearch/modules/lang-painless/antlr4-runtime-4.13.1.jar
- /usr/local/opensearch/modules/lang-painless/asm-9.7.jar
- /usr/local/opensearch/modules/lang-painless/asm-analysis-9.7.jar
- /usr/local/opensearch/modules/lang-painless/asm-commons-9.7.jar
- /usr/local/opensearch/modules/lang-painless/asm-tree-9.7.jar
- /usr/local/opensearch/modules/lang-painless/asm-util-9.7.jar
- /usr/local/opensearch/modules/lang-painless/lang-painless-3.4.0.jar
- /usr/local/opensearch/modules/lang-painless/opensearch-scripting-painless-spi-3.4.0.jar
- /usr/local/opensearch/modules/lang-painless/plugin-descriptor.properties
- /usr/local/opensearch/modules/lang-painless/plugin-security.policy
- /usr/local/opensearch/modules/mapper-extras/
- /usr/local/opensearch/modules/mapper-extras/mapper-extras-client-3.4.0.jar
- /usr/local/opensearch/modules/mapper-extras/plugin-descriptor.properties
- /usr/local/opensearch/modules/opensearch-dashboards/
- /usr/local/opensearch/modules/opensearch-dashboards/commons-codec-1.18.0.jar
- /usr/local/opensearch/modules/opensearch-dashboards/commons-logging-1.3.5.jar
- /usr/local/opensearch/modules/opensearch-dashboards/httpclient5-5.4.4.jar
- /usr/local/opensearch/modules/opensearch-dashboards/httpcore5-5.3.4.jar
- /usr/local/opensearch/modules/opensearch-dashboards/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/modules/opensearch-dashboards/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/modules/opensearch-dashboards/opensearch-dashboards-3.4.0.jar
- /usr/local/opensearch/modules/opensearch-dashboards/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/modules/opensearch-dashboards/opensearch-ssl-config-3.4.0.jar
- /usr/local/opensearch/modules/opensearch-dashboards/plugin-descriptor.properties
- /usr/local/opensearch/modules/opensearch-dashboards/reindex-client-3.4.0.jar
- /usr/local/opensearch/modules/opensearch-dashboards/slf4j-api-2.0.17.jar
- /usr/local/opensearch/modules/parent-join/
- /usr/local/opensearch/modules/parent-join/parent-join-client-3.4.0.jar
- /usr/local/opensearch/modules/parent-join/plugin-descriptor.properties
- /usr/local/opensearch/modules/percolator/
- /usr/local/opensearch/modules/percolator/percolator-client-3.4.0.jar
- /usr/local/opensearch/modules/percolator/plugin-descriptor.properties
- /usr/local/opensearch/modules/rank-eval/
- /usr/local/opensearch/modules/rank-eval/plugin-descriptor.properties
- /usr/local/opensearch/modules/rank-eval/rank-eval-client-3.4.0.jar
- /usr/local/opensearch/modules/reindex/
- /usr/local/opensearch/modules/reindex/commons-codec-1.18.0.jar
- /usr/local/opensearch/modules/reindex/commons-logging-1.3.5.jar
- /usr/local/opensearch/modules/reindex/httpclient5-5.4.4.jar
- /usr/local/opensearch/modules/reindex/httpcore5-5.3.4.jar
- /usr/local/opensearch/modules/reindex/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/modules/reindex/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/modules/reindex/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/modules/reindex/opensearch-ssl-config-3.4.0.jar
- /usr/local/opensearch/modules/reindex/parent-join/
- /usr/local/opensearch/modules/reindex/parent-join/plugin-descriptor.properties
- /usr/local/opensearch/modules/reindex/plugin-descriptor.properties
- /usr/local/opensearch/modules/reindex/plugin-security.policy
- /usr/local/opensearch/modules/reindex/reindex-client-3.4.0.jar
- /usr/local/opensearch/modules/reindex/slf4j-api-2.0.17.jar
- /usr/local/opensearch/modules/reindex/transport-netty4/
- /usr/local/opensearch/modules/reindex/transport-netty4/plugin-descriptor.properties
- /usr/local/opensearch/modules/reindex/transport-netty4/plugin-security.policy
- /usr/local/opensearch/modules/repository-url/
- /usr/local/opensearch/modules/repository-url/plugin-descriptor.properties
- /usr/local/opensearch/modules/repository-url/plugin-security.policy
- /usr/local/opensearch/modules/repository-url/repository-url-3.4.0.jar
- /usr/local/opensearch/modules/rule-framework/
- /usr/local/opensearch/modules/rule-framework/autotagging-commons-spi-3.4.0.jar
- /usr/local/opensearch/modules/rule-framework/common-3.4.0.jar
- /usr/local/opensearch/modules/rule-framework/commons-collections4-4.5.0.jar
- /usr/local/opensearch/modules/rule-framework/plugin-descriptor.properties
- /usr/local/opensearch/modules/rule-framework/rule-framework-3.4.0.jar
- /usr/local/opensearch/modules/search-pipeline-common/
- /usr/local/opensearch/modules/search-pipeline-common/plugin-descriptor.properties
- /usr/local/opensearch/modules/search-pipeline-common/search-pipeline-common-3.4.0.jar
- /usr/local/opensearch/modules/store-subdirectory/
- /usr/local/opensearch/modules/store-subdirectory/plugin-descriptor.properties
- /usr/local/opensearch/modules/store-subdirectory/store-subdirectory-3.4.0.jar
- /usr/local/opensearch/modules/systemd/
- /usr/local/opensearch/modules/systemd/plugin-descriptor.properties
- /usr/local/opensearch/modules/systemd/plugin-security.policy
- /usr/local/opensearch/modules/systemd/systemd-3.4.0.jar
- /usr/local/opensearch/modules/transport-grpc/
- /usr/local/opensearch/modules/transport-grpc/error_prone_annotations-2.24.1.jar
- /usr/local/opensearch/modules/transport-grpc/failureaccess-1.0.2.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-api-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-core-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-netty-shaded-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-protobuf-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-protobuf-lite-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-services-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-stub-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/grpc-util-1.75.0.jar
- /usr/local/opensearch/modules/transport-grpc/guava-33.2.1-jre.jar
- /usr/local/opensearch/modules/transport-grpc/perfmark-api-0.27.0.jar
- /usr/local/opensearch/modules/transport-grpc/plugin-descriptor.properties
- /usr/local/opensearch/modules/transport-grpc/plugin-security.policy
- /usr/local/opensearch/modules/transport-grpc/protobufs-0.24.0.jar
- /usr/local/opensearch/modules/transport-grpc/transport-grpc-3.4.0.jar
- /usr/local/opensearch/modules/transport-grpc/transport-grpc-spi-3.4.0.jar
- /usr/local/opensearch/modules/transport-netty4/
- /usr/local/opensearch/modules/transport-netty4/netty-buffer-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-codec-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-codec-base-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-codec-compression-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-codec-http-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-codec-http2-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-common-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-handler-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-resolver-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-transport-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/netty-transport-native-unix-common-4.2.7.Final.jar
- /usr/local/opensearch/modules/transport-netty4/plugin-descriptor.properties
- /usr/local/opensearch/modules/transport-netty4/plugin-security.policy
- /usr/local/opensearch/modules/transport-netty4/transport-netty4-client-3.4.0.jar
- /usr/local/opensearch/opensearch-security-analytics/
- /usr/local/opensearch/opensearch-security-analytics/rules/
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_aad_secops_signin_failure_bad_password_threshold.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_aadhybridhealth_adfs_new_server.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_aadhybridhealth_adfs_service_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_bitlocker_key_retrieval.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_device_registration_or_join_without_mfa.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_device_registration_policy_changes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_sign_ins_from_noncompliant_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_sign_ins_from_unknown_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_user_added_to_admin_role.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/azure_ad_users_added_to_device_admin_roles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/ad_ldap/win_ldap_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/apache_access/
- /usr/local/opensearch/opensearch-security-analytics/rules/apache_access/web_apache_segfault.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/apache_access/web_apache_threading_error.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aad_secops_ca_policy_removedby_bad_actor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aad_secops_ca_policy_updatedby_bad_actor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aad_secops_new_ca_policy_addedby_bad_actor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aad_secops_signin_failure_bad_password_threshold.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aadhybridhealth_adfs_new_server.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_aadhybridhealth_adfs_service_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_account_lockout.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_account_created_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_auth_failure_increase.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_auth_sucess_increase.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_auth_to_important_apps_using_single_factor_auth.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_authentications_from_countries_you_do_not_operate_out_of.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_azurehound_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_bitlocker_key_retrieval.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_device_registration_or_join_without_mfa.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_device_registration_policy_changes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_failed_auth_from_countries_you_do_not_operate_out_of.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_guest_users_invited_to_tenant_by_non_approved_inviters.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_only_single_factor_auth_required.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_risky_sign_ins_with_singlefactorauth_from_unknown_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_sign_ins_from_noncompliant_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_sign_ins_from_unknown_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_suspicious_signin_bypassing_mfa.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_user_added_to_admin_role.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_ad_users_added_to_device_admin_roles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_appid_uri_changes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_credential_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_credential_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_delegated_permissions_all_users.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_device_code_authentication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_end_user_consent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_end_user_consent_blocked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_owner_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_permissions_msft.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_privileged_permissions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_role_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_ropc_authentication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_app_uri_modifications.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_application_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_application_gateway_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_application_security_group_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_blocked_account_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_change_to_authentication_method.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_conditional_access_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_container_registry_created_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_creating_number_of_resources_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_device_no_longer_managed_or_compliant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_device_or_configuration_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_dns_zone_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_federation_modified.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_firewall_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_firewall_rule_collection_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_granting_permission_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_group_user_addition_ca_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_group_user_removal_ca_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_guest_invite_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_guest_to_member.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_anomalous_token.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_anomalous_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_anonymous_ip_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_anonymous_ip_address.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_atypical_travel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_impossible_travel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_inbox_forwarding_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_inbox_manipulation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_leaked_credentials.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_malicious_ip_address.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_malicious_ip_address_suspicious.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_malware_linked_ip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_new_coutry_region.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_password_spray.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_prt_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_suspicious_browser.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_threat_intel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_token_issuer_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_identity_protection_unfamilar_sign_in.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_keyvault_key_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_keyvault_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_keyvault_secrets_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_admission_controller.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_cluster_created_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_cronjob.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_events_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_network_policy_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_pods_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_role_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_rolebinding_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_secret_or_config_object_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_kubernetes_service_account_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_legacy_authentication_protocols.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_login_to_disabled_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_mfa_denies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_mfa_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_mfa_interrupted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_network_firewall_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_network_firewall_rule_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_network_p2s_vpn_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_network_security_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_network_virtual_device_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_new_cloudshell_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_owner_removed_from_application_or_service_principal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_account_stale.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_activation_approve_deny.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_alerts_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_change_settings.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_invalid_license.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_role_assigned_outside_of_pim.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_role_frequent_activation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_role_no_mfa_required.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_role_not_used.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_pim_too_many_global_admins.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_priviledged_role_assignment_add.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_priviledged_role_assignment_bulk_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_privileged_account_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_rare_operations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_service_principal_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_service_principal_removed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_subscription_permissions_elevation_via_activitylogs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_subscription_permissions_elevation_via_auditlogs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_suppression_rule_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_tap_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_unusual_authentication_interruption.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_user_login_blocked_by_conditional_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_user_password_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_users_authenticating_to_other_azure_ad_tenants.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_virtual_network_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/azure/azure_vpn_connection_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_attached_malicious_lambda_layer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_cloudtrail_disable_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_config_disable_recording.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_console_getsignintoken.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_create_load_balancer_layer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_delete_identity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_disable_bucket_versioning.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ec2_disable_encryption.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ec2_download_userdata.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ec2_startup_script_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ec2_vm_export_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ecs_task_definition_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_ecs_task_definition_cred_endpoint_query.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_efs_fileshare_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_efs_fileshare_mount_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_eks_cluster_created_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_elasticache_security_group_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_elasticache_security_group_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_enum_buckets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_enum_listing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_guardduty_disruption.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_iam_backdoor_users_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_iam_s3browser_loginprofile_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_iam_s3browser_templated_s3_bucket_policy_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_iam_s3browser_user_or_accesskey_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_lambda_function_created_or_invoked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_macic_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_passed_role_to_glue_development_endpoint.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_rds_change_master_password.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_rds_public_db_restore.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_root_account_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_route_53_domain_transferred_lock_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_route_53_domain_transferred_to_another_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_securityhub_finding_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_snapshot_backup_exfiltration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_sso_idp_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_sts_assumerole_misuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_sts_getsessiontoken_misuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_susp_saml_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/cloudtrail/aws_update_login_profile.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_c2_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_external_service_interaction_domains.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_high_bytes_out.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_high_null_records_requests_rate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_high_requests_rate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_high_txt_records_requests_rate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_mal_cobaltstrike.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_pua_cryptocoin_mining_xmr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_susp_b64_queries.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_susp_telegram_api.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_susp_txt_exec_strings.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/dns/net_dns_wannacry_killswitch_domain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_delete_action_invoked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_disable_high_risk_configuration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_disabled_outdated_dependency_or_vulnerability.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_new_org_member.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_new_secret_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_outside_collaborator_detected.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_push_protection_bypass_detected.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_push_protection_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_secret_scanning_feature_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/github/github_self_hosted_runner_changes_detected.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_application_access_levels_modified.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_application_removed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_granted_domain_api_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_mfa_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_role_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_role_privilege_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/gworkspace/gcp_gworkspace_user_granted_admin_privileges.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_audio_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_auditing_config_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_binary_padding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_bpfdoor_file_accessed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_bpfdoor_port_redirect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_capabilities_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_change_file_time_attr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_chattr_immutable_removal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_clipboard_collection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_clipboard_image_collection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_coinminer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_create_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_data_compressed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_data_exfil_wget.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_dd_delete_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_disable_system_firewall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_file_or_folder_permissions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_find_cred_in_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_hidden_binary_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_hidden_files_directories.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_hidden_zip_files_steganography.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_keylogging_with_pam_d.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_ld_so_preload_mod.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_load_module_insmod.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_logging_config_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_masquerading_crond.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_modify_system_firewall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_network_service_scanning.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_network_sniffing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_omigod_scx_runasprovider_executeshellcommand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_password_policy_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_pers_systemd_reload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_screencapture_import.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_screencaputre_xwd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_split_file_into_pieces.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_steghide_embed_steganography.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_steghide_extract_steganography.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_susp_c2_commands.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_susp_cmds.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_susp_exe_folders.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_susp_histfile_operations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_system_info_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_system_info_discovery2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_system_shutdown_reboot.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_systemd_service_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_unix_shell_configuration_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_unzip_hidden_zip_files_steganography.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_user_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/auditd/lnx_auditd_web_rce.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/auth/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/auth/lnx_auth_pwnkit_local_privilege_escalation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/clamav/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/clamav/lnx_clamav_relevant_message.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/cron/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/cron/lnx_cron_crontab_file_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/guacamole/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/guacamole/lnx_guacamole_susp_guacamole.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_apt_equationgroup_lnx.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_buffer_overflows.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_clear_syslog.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_file_copy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_ldso_preload_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_nimbuspwn_privilege_escalation_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_potential_susp_ebpf_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_privileged_user_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_shell_clear_cmd_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_shell_susp_commands.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_shell_susp_log_entries.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_shell_susp_rev_shells.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_shellshock.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_space_after_filename_.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_susp_dev_tcp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_susp_jexboss.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/lnx_symlink_etc_passwd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/sshd/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/sshd/lnx_sshd_ssh_cve_2018_15473.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/sshd/lnx_sshd_susp_ssh.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/sudo/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/sudo/lnx_sudo_cve_2019_14287_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/syslog/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/syslog/lnx_syslog_security_tools_disabling_syslog.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/syslog/lnx_syslog_susp_named.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/vsftpd/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/builtin/vsftpd/lnx_vsftpd_susp_error_messages.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_doas_conf_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_persistence_cron_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_persistence_sudoers_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_susp_shell_script_under_profile_directory.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_triple_cross_rootkit_lock_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_triple_cross_rootkit_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/file_event/file_event_lnx_wget_download_file_in_tmp_dir.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/network_connection/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/network_connection/net_connection_lnx_back_connect_shell_dev.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/network_connection/net_connection_lnx_crypto_mining_indicators.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/network_connection/net_connection_lnx_ngrok_tunnel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_at_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_base64_decode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_base64_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_base64_shebang_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_bash_interactive_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_bpf_kprob_tracing_enabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_bpftrace_unsafe_option_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_capa_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_cat_sudoers.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_chattr_immutable_removal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_clear_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_clear_syslog.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_clipboard_collection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_cp_passwd_or_shadow_tmp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_crontab_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_crontab_removal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_crypto_mining.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_curl_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_cve_2022_26134_atlassian_confluence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_cve_2022_33891_spark_shell_command_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_dd_file_overwrite.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_dd_process_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_disable_ufw.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_doas_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_network_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_permission_change_admin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_storage_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_syslog_config_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_system_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_user_account_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_vm_kill.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_esxcli_vsan_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_file_and_directory_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_file_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_grep_os_arch_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_groupdel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_gtfobin_apt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_gtfobin_vim.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_install_root_certificate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_install_suspicioua_packages.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_iptables_flush_ufw.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_kill_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_local_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_local_groups.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_malware_gobrat_grep_payload_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_mkfifo_named_pipe_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_mkfifo_named_pipe_creation_susp_location.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_mount_hidepid.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_netcat_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_nohup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_nohup_susp_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executescript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_omigod_scx_runasprovider_executeshellcommand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_perl_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_php_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_process_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_proxy_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_python_pty_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_python_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_remote_access_tools_teamviewer_incoming_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_remote_system_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_remove_package.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_ruby_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_schedule_task_job_cron.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_security_software_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_security_tools_disabling.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_services_stop_and_disable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_setgid_setuid.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_ssm_agent_abuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_sudo_cve_2019_14287.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_chmod_directories.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_container_residence_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_curl_fileupload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_curl_useragent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_dockerenv_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_execution_tmp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_find_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_git_clone.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_history_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_history_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_hktl_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_inod_listing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_interactive_bash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_java_children.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_network_utilities_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_pipe_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_recon_indicators.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_sensitive_file_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_shell_child_process_from_parent_tmp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_susp_shell_script_exec_from_susp_location.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_system_info_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_system_network_connections_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_system_network_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_touch_susp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_triple_cross_rootkit_execve_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_triple_cross_rootkit_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_userdel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_usermod_susp_group.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_webshell_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_wget_download_suspicious_directory.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/linux/process_creation/proc_creation_lnx_xterm_reverse_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_activity_by_terminated_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_activity_from_anonymous_ip_addresses.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_activity_from_infrequent_country.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_data_exfiltration_to_unsanctioned_app.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_disabling_mfa.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_from_susp_ip_addresses.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_impossible_travel_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_logon_from_risky_ip_address.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_new_federated_domain_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_new_federated_domain_added_audit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_new_federated_domain_added_exchange.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_potential_ransomware_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_pst_export_alert.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_pst_export_alert_using_new_compliancesearchaction.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_susp_inbox_forwarding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_susp_oauth_app_file_download_activities.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_unusual_volume_of_file_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/m365/microsoft365_user_restricted_from_sending_email.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_clear_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_collect_data.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_crypto_actions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_disable_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_dos.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_file_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_input_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_local_accounts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_modify_config.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_moving_data.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/aaa/cisco_cli_net_sniff.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/bgp/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/bgp/cisco_bgp_md5_auth_failed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/ldp/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/cisco/ldp/cisco_ldp_md5_auth_failed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/net_firewall_cleartext_protocols.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/net_firewall_high_dns_bytes_out.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/net_firewall_high_dns_requests_rate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/net_firewall_susp_network_scan_by_ip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/firewall/net_firewall_susp_network_scan_by_port.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_domain_user_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_mitre_bzar_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_mitre_bzar_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_printnightmare_print_driver_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dce_rpc_smb_spoolss_named_pipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_default_cobalt_strike_certificate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dns_mining_pools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dns_nkn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dns_susp_zbit_flag.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_dns_torproxy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_http_executable_download_from_webdav.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_http_omigod_no_auth_rce.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_http_webdav_put_request.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_rdp_public_listener.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_atsvc_task.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_impacket_secretdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_lm_namedpipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_susp_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_susp_raccess_sensitive_fext.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_smb_converted_win_transferring_files_with_credential_data.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/network/zeek/zeek_susp_kerberos_rc4.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_admin_role_assigned_to_user_or_group.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_admin_role_assignment_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_api_token_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_api_token_revoked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_application_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_application_sign_on_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_mfa_reset_or_deactivated.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_network_zone_deactivated_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_policy_rule_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_security_threat_detected.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_unauthorized_access_to_app.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/okta/okta_user_account_locked_out.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_exploiting.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_hacktool.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_password_dumper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_printernightmare_cve_2021_34527.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_relevant_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/antivirus/av_webshell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/django/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/django/appframework_django_exceptions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/python/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/python/app_python_sql_exceptions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_atsvc_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_atsvc_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_dcsync_attack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_efs_abuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_eventlog_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_itaskschedulerservice_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_itaskschedulerservice_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_printing_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_remote_dcom_or_wmi.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_remote_registry_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_remote_registry_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_remote_server_service_abuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_remote_service_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_sasec_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_sasec_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_sharphound_recon_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/rpc_firewall/rpc_firewall_sharphound_recon_sessions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/ruby/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/ruby/appframework_ruby_on_rails_exceptions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/spring/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/spring/appframework_spring_exceptions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/sql/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_application/sql/app_sqlinjection_errors.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_apt/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_apt/apt_silence_downloader_v3.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_apt/apt_silence_eda.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_aad_secops_signin_failure_bad_password_threshold.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_aadhybridhealth_adfs_new_server.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_aadhybridhealth_adfs_service_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_account_lockout.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_bitlocker_key_retrieval.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_device_registration_or_join_without_mfa.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_device_registration_policy_changes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_sign_ins_from_noncompliant_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_sign_ins_from_unknown_devices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_user_added_to_admin_role.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_ad_users_added_to_device_admin_roles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_appid_uri_changes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_credential_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_credential_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_device_code_authentication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_owner_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_ropc_authentication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_app_uri_modifications.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_application_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_application_gateway_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_application_security_group_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_blocked_account_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_change_to_authentication_method.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_conditional_access_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_container_registry_created_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_creating_number_of_resources_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_device_no_longer_managed_or_compliant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_device_or_configuration_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_dns_zone_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_federation_modified.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_firewall_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_firewall_rule_collection_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_granting_permission_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_keyvault_key_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_keyvault_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_keyvault_secrets_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_admission_controller.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_cluster_created_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_cronjob.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_events_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_network_policy_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_pods_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_role_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_rolebinding_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_secret_or_config_object_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_kubernetes_service_account_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_login_to_disabled_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_mfa_denies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_mfa_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_mfa_interrupted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_network_firewall_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_network_firewall_rule_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_network_p2s_vpn_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_network_security_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_network_virtual_device_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_new_cloudshell_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_owner_removed_from_application_or_service_principal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_rare_operations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_service_principal_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_service_principal_removed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_subscription_permissions_elevation_via_activitylogs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_subscription_permissions_elevation_via_auditlogs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_suppression_rule_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_unusual_authentication_interruption.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_user_login_blocked_by_conditional_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_virtual_network_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/azure/azure_vpn_connection_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_bucket_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_bucket_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_dlp_re_identifies_sensitive_information.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_dns_zone_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_firewall_rule_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_full_network_traffic_packet_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_kubernetes_admission_controller.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_kubernetes_cronjob.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_kubernetes_rolebinding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_kubernetes_secrets_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_service_account_disabled_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_service_account_modified.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_sql_database_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gcp/gcp_vpn_tunnel_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_application_removed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_granted_domain_api_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_mfa_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_role_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_role_privilege_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/gworkspace/gworkspace_user_granted_admin_privileges.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_activity_by_terminated_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_activity_from_anonymous_ip_addresses.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_activity_from_infrequent_country.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_data_exfiltration_to_unsanctioned_app.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_from_susp_ip_addresses.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_impossible_travel_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_logon_from_risky_ip_address.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_new_federated_domain_added.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_potential_ransomware_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_susp_inbox_forwarding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_susp_oauth_app_file_download_activities.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_unusual_volume_of_file_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/m365/microsoft365_user_restricted_from_sending_email.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_admin_role_assigned_to_user_or_group.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_api_token_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_api_token_revoked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_application_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_application_sign_on_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_mfa_reset_or_deactivated.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_network_zone_deactivated_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_policy_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_policy_rule_modified_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_security_threat_detected.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_unauthorized_access_to_app.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/okta/okta_user_account_locked_out.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/onelogin/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/onelogin/onelogin_assumed_another_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_cloud/onelogin/onelogin_user_account_locked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/default_credentials_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/firewall_cleartext_protocols.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/group_modification_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/host_without_firewall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/netflow_cleartext_protocols.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_compliance/workstation_was_locked.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/file_event/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/file_event/file_event_macos_emond_launch_daemon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/file_event/file_event_macos_startup_items.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_applescript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_base64_decode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_binary_padding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_change_file_time_attr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_clear_system_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_create_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_create_hidden_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_creds_from_keychain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_disable_security_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_file_and_directory_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_find_cred_in_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_gui_input_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_local_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_local_groups.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_network_service_scanning.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_network_sniffing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_remote_system_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_schedule_task_job_cron.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_screencapture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_security_software_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_space_after_filename.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_split_file_into_pieces.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_susp_histfile_operations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_susp_macos_firmware_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_system_network_connections_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_system_network_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_system_shutdown_reboot.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_macos/process_creation/proc_creation_macos_xattr_gatekeeper_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_apt40.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_apt_domestic_kitten.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_baby_shark.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_chafer_malware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_cobalt_amazon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_cobalt_malformed_uas.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_cobalt_ocsp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_cobalt_onedrive.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_download_susp_dyndns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_download_susp_tlds_blacklist.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_download_susp_tlds_whitelist.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_downloadcradle_webdav.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_empire_ua_uri_combos.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_empty_ua.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ios_implant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_java_class_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_powershell_ua.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_pwndrop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_raw_paste_service_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_susp_flash_download_loc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_telegram_api.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_turla_comrat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_apt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_bitsadmin_susp_ip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_bitsadmin_susp_tld.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_cryptominer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_frameworks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_hacktool.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_malware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ua_susp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ursnif_malware_c2_url.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_proxy/proxy_ursnif_malware_download_url.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_apache_segfault.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_apache_threading_error.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2010_5278_exploitation_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2018_13379_fortinet_preauth_read_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2018_2894_weblogic_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2019_11510_pulsesecure_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2019_19781_citrix_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2019_3398_confluence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_0688_exchange_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_0688_msexchange.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_10148_solarwinds_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_14882_weblogic_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_28188_terramaster_rce_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_3452_cisco_asa_ftd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_5902_f5_bigip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2020_8193_8195_citrix_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_20090_2021_20091_arcadyan_router_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_2109_weblogic_rce_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_21972_vsphere_unauth_rce_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_21978_vmware_view_planner_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_22005_vmware_file_upload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_22123_fortinet_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_22893_pulse_secure_rce_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_26814_wzuh_rce.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_26858_iis_rce.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_28480_exchange_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_33766_msexchange_proxytoken.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_40539_adselfservice.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_40539_manageengine_adselfservice_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_41773_apache_path_traversal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_42237_sitecore_report_ashx.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_43798_grafana.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_44228_log4j.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_cve_2021_44228_log4j_fields.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_exchange_exploitation_hafnium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_exchange_proxyshell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_exchange_proxyshell_successful.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_iis_tilt_shortname_scan.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_java_payload_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_jndi_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_multiple_susp_resp_codes_single_source.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_nginx_core_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_path_traversal_exploitation_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_solarwinds_supernova_webshell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_sonicwall_jarrewrite_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_source_code_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_sql_injection_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_ssti_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_susp_windows_path_uri.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_unc2546_dewmode_php_webshell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_webshell_regeorg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_win_webshells_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/others_web/web_xss_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/rule_categories.json
- /usr/local/opensearch/opensearch-security-analytics/rules/s3/
- /usr/local/opensearch/opensearch-security-analytics/rules/s3/aws_s3_data_management_tampering.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/dns_query_win_regsvr32_network_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/net_connection_win_regsvr32_network_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/proc_creation_win_susp_regsvr32_no_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/proc_creation_win_system_exe_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/test_windows/win_sample_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/aws_waf/
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/aws_waf/aws_waf_web_susp_useragents.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/web_cve_2023_25717_ruckus_wireless_admin_exploit_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/web_sql_injection_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/web_susp_useragents.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/waf/web_xss_in_access_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_audit_cve.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_av_relevant_match.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_builtin_remove_application.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_software_atera_rmm_agent_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_susp_backup_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_susp_msmpeng_crash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_vul_cve_2020_0688.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/application/win_vul_cve_2021_41379.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/applocker/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/applocker/win_applocker_file_was_not_allowed_to_run.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_susp_domain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_susp_local_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_susp_local_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_susp_powershell_job.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_susp_use_bitsadmin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/bits_client/win_bits_client_uncommon_domain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/code_integrity/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/code_integrity/win_codeintegrity_failed_driver_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/dns_server/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/dns_server/win_apt_gallium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/dns_server/win_susp_dns_config.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/driverframeworks/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/driverframeworks/win_usb_device_plugged.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_add_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_change_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_delete_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_failed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_reset.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/firewall_as/win_firewall_as_setting_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ldap/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ldap/win_ldap_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_cve_2021_42321.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_proxylogon_oabvirtualdir.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_proxyshell_certificate_generation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_proxyshell_mailbox_export.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_proxyshell_remove_mailbox_export.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_transportagent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_exchange_transportagent_failed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/msexchange/win_set_oabvirtualdirectory_externalurl.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ntlm/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ntlm/win_susp_ntlm_auth.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ntlm/win_susp_ntlm_brute_force.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/ntlm/win_susp_ntlm_rdp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/printservice/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/printservice/win_exploit_cve_2021_1675_printspooler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/printservice/win_exploit_cve_2021_1675_printspooler_operational.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_aadhealth_mon_agent_regkey_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_aadhealth_svc_agent_regkey_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_account_backdoor_dcsync_rights.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_account_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_ad_object_writedac_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_ad_replication_non_machine_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_ad_user_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_adcs_certificate_template_configuration_vulnerability.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_adcs_certificate_template_configuration_vulnerability_eku.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_admin_rdp_login.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_admin_share_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_alert_active_directory_user_control.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_alert_ad_user_backdoors.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_alert_enable_weak_encryption.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_alert_ruler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_apt_chafer_mar18_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_apt_slingshot.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_apt_wocao.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_atsvc_task.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_camera_microphone_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_dce_rpc_smb_spoolss_named_pipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_dcom_iertutil_dll_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_dcsync.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_defender_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_disable_event_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_dpapi_domain_backupkey_extraction.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_dpapi_domain_masterkey_backup_attempt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_etw_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_event_log_cleared.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_exploit_cve_2021_1675_printspooler_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_external_device.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_global_catalog_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_gpo_scheduledtasks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_hidden_user_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_hybridconnectionmgr_svc_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_impacket_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_impacket_secretdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_clip_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_obfuscated_iex_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_stdin_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_var_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_compress_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_rundll_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_stdin_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_use_clip_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_use_mshta_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_use_rundll32_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_invoke_obfuscation_via_var_services_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_iso_mount.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_lm_namedpipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_lolbas_execution_of_nltest.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_lsass_access_non_system_account.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_mal_wceaux_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_metasploit_authentication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_net_ntlm_downgrade.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_net_share_obj_susp_desktop_ini.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_new_or_renamed_user_account_with_dollar_sign.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_not_allowed_rdp_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_overpass_the_hash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_pass_the_hash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_pass_the_hash_2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_petitpotam_network_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_petitpotam_susp_tgt_request.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_possible_dc_shadow.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_privesc_cve_2020_1472.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_protected_storage_service_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_rare_schtasks_creations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_rdp_bluekeep_poc_scanner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_rdp_localhost_login.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_rdp_reverse_tunnel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_register_new_logon_process_by_rubeus.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_remote_powershell_session.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_remote_registry_management_using_reg_utility.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_sam_registry_hive_handle_request.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_samaccountname_spoofing_cve_2021_42287.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_scheduled_task_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_scm_database_handle_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_scm_database_privileged_operation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_scrcons_remote_wmi_scripteventconsumer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_mal_creddumper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_mal_service_installs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_metasploit_or_impacket_smb_psexec_service_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_meterpreter_or_cobaltstrike_getsystem_service_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_powershell_script_installed_as_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_tap_driver_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_security_wmi_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_smb_file_creation_admin_shares.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_add_domain_trust.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_add_sid_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_codeintegrity_check_failure.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_dsrm_password_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_eventlog_cleared.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logon_reasons.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logon_source.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_explicit_credentials.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source_kerberos.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source_kerberos2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source_kerberos3.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source_ntlm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_logons_single_source_ntlm2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_failed_remote_logons_single_source.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_interactive_logons.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_kerberos_manipulation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_krbrelayup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_ldap_dataexchange.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_local_anon_logon_created.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_logon_explicit_credentials.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_lsass_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_lsass_dump_generic.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_multiple_files_renamed_or_deleted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_net_recon_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_opened_encrypted_zip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_opened_encrypted_zip_filename.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_opened_encrypted_zip_outlook.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_outbound_kerberos_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_raccess_sensitive_fext.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_rc4_kerberos.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_rottenpotato.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_samr_pwset.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_sdelete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_time_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_susp_wmi_login.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_svcctl_remote_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_syskey_registry_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_sysmon_channel_reference_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_transferring_files_with_credential_data_via_network_shares.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_user_added_to_local_administrators.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_user_couldnt_call_privileged_service_lsaregisterlogonprocess.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_user_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_user_driver_loaded.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_vssaudit_secevent_source_registration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/security/win_wmiprvse_wbemcomn_dll_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/servicebus/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/servicebus/win_hybridconnectionmgr_svc_running.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/smbclient/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/smbclient/win_susp_failed_guest_logon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_apt_carbonpaper_turla.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_apt_chafer_mar18_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_apt_stonedrill.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_apt_turla_service_png.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_cobaltstrike_service_installs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_eventlog_cleared.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_hack_smbexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_clip_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_obfuscated_iex_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_stdin_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_var_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_compress_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_rundll_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_stdin_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_use_clip_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_use_mshta_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_use_rundll32_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_invoke_obfuscation_via_var_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_lsasrv_ntlmv1.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_mal_creddumper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_meterpreter_or_cobaltstrike_getsystem_service_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_moriya_rootkit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_ntfs_vuln_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_pcap_drivers.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_possible_zerologon_exploitation_using_wellknown_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_powershell_script_installed_as_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_quarkspwdump_clearing_hive_access_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_rare_service_installs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_rdp_potential_cve_2019_0708.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_sample_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_security_krbrelayup_service_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_service_hacktools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_service_install_susp_double_ampersand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_dhcp_config.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_dhcp_config_failed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_proceshacker.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_sam_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_service_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_service_installation_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_service_installation_folder_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_service_installation_script.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_susp_system_update_error.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_system_application_sysmon_crash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_system_defender_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_system_susp_eventlog_cleared.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_tap_driver_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_tool_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_volume_shadow_copy_mount.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_vul_cve_2020_1472.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/system/win_vul_cve_2021_42278_or_cve_2021_42287.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/taskscheduler/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/taskscheduler/win_rare_schtask_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/terminalservices/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/terminalservices/win_terminalservices_rdp_ngrok.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/win_alert_mimikatz_keywords.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/win_susp_logon_newcredentials.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_alert_lsass_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_amsi_trigger.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_exclusions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_history_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_psexec_wmi_asr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_tamper_protection_trigger.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/windefend/win_defender_threat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/wmi/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/builtin/wmi/win_wmi_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/create_remote_thread_win_susp_targets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/create_remote_thread_win_ttdinjec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_cactustorch.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_cobaltstrike_process_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_createremotethread_loadlibrary.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_password_dumper_keepass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_password_dumper_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_powershell_code_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_susp_powershell_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_remote_thread/sysmon_susp_remote_thread.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_stream_hash/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_stream_hash/sysmon_ads_executable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/create_stream_hash/sysmon_regedit_export_to_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_ammyy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_gotoopener.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_hybridconnectionmgr_servicebus.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_lobas_appinstaller.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_logmein.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_mal_cobaltstrike.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_mega_nz.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_possible_dns_rebinding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_regsvr32_network_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_susp_ipify.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_susp_teamviewer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_tor_onion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/dns_query/dns_query_win_ufile_io.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_mal_creddumper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_meterpreter_or_cobaltstrike_getsystem_service_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_powershell_script_installed_as_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_susp_temp_use.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_vuln_dell_driver.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/driver_load/driver_load_windivert.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_access/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_access/file_access_win_browser_credential_stealing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/file_delete_win_cve_2021_1675_printspooler_del.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/file_delete_win_delete_appli_log.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/file_delete_win_delete_backup_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/file_delete_win_delete_prefetch.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_delete/file_delete_win_sysinternals_sdelete_file_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_access_susp_unattend_xml.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_advanced_ip_scanner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_anydesk_artefact.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_apt_unidentified_nov_18.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_crackmapexec_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_creation_new_shim_database.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_creation_scr_binary_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_creation_system_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_creation_unquoted_service_path.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cred_dump_tools_dropped_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_csharp_compile_artefact.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2021_1675_printspooler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2021_26858_msexchange.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2021_31979_cve_2021_33771_exploits.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2021_41379_msi_lpe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2021_44077_poc_default_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_cve_2022_24527_lpe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_detect_powerup_dllhijacking.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_ghostpack_safetykatz.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_gotoopener_artefact.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_hack_dumpert.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_hivenightmare_file_exports.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_hktl_nppspy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_install_teamviewer_desktop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_iso_file_recent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_lsass_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_lsass_memory_dump_file_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_lsass_werfault_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_macro_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_mal_adwind.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_mal_octopus_scanner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_mal_vhd_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_mimikatz_kirbi_file_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_mimimaktz_memssp_log_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_moriya_rootkit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_new_src_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_notepad_plus_plus_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_ntds_dit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_ntds_exfil_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_office_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_outlook_c2_macro_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_outlook_newform.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_pcre_net_temp_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_pingback_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_powershell_exploit_scripts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_powershell_startup_shortcuts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_quarkspw_filedump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_rclone_exec_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_redmimicry_winnti_filedrop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_sam_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_screenconnect_artefact.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_script_creation_by_office_using_file_ext.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_startup_folder_file_write.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_adsi_cache_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_clr_logs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_colorcpl.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_creation_by_mobsync.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_default_gpo_dir_write.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_desktop_ini.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_desktop_txt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_desktopimgdownldr_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_diagcab.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_dropper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_exchange_aspx_write.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_get_variable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_ntds_dit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_pfx_file_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_powershell_profile_create.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_procexplorer_driver_created_in_tmp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_system_interactive_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_task_write.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_teamviewer_remote_session.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_susp_winword_startup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_tool_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_tsclient_filewrite_startup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_consent_comctl32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_dotnet_profiler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_eventvwr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_idiagnostic_profile.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_ieinstal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_msconfig_gui.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_ntfs_reparse_point.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_winsat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_uac_bypass_wmp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_webshell_creation_detect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_werfault_dll_hijacking.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_win_cscript_wscript_dropper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_win_shell_write_susp_directory.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_winrm_awl_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_winword_cve_2021_40444.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_wmi_persistence_script_event_consumer_write.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_wmiprvse_wbemcomn_dll_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_word_template_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_event/file_event_win_writing_local_admin_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_rename/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/file_rename/file_rename_win_not_dll_to_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_abusing_azure_browser_sso.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_alternate_powershell_hosts_moduleload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_foggyweb_nobelium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_in_memory_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_mimikatz_inmemory_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_msdt_sdiageng.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_pcre_net_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_pingback_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_scrcons_imageload_wmi_scripteventconsumer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_silenttrinity_stage_use.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_spoolsv_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_advapi32_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_dbghelp_dbgcore_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_fax_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_image_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_office_dotnet_assembly_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_office_dotnet_clr_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_office_dotnet_gac_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_office_dsparse_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_office_kerberos_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_python_image_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_script_dotnet_clr_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_system_drawing_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_vss_ps_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_susp_winword_vbadll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_svchost_dll_search_order_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_tttracer_mod_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_uac_bypass_via_dism.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_uipromptforcreds_dlls.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_unsigned_image_loaded_into_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_usp_svchost_clfsw32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_wmi_module_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_wmi_persistence_commandline_event_consumer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_wmic_remote_xsl_scripting_dlls.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_wmiprvse_wbemcomn_dll_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/image_load/image_load_wsman_provider_image_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_susp_win_binary_no_cmdline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_binary_github_com.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_binary_susp_com.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_crypto_mining.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_dllhost_net_connections.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_eqnedt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_excel_outbound_network_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_imewdbld.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_malware_backconnect_ports.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_mega_nz.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_msiexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_notepad_network_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_powershell_network_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_python.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_rdp_reverse_tunnel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_rdp_to_http.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_regsvr32_network_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_remote_powershell_session_network.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_rundll32_net_connections.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_silenttrinity_stager_msbuild_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_dropbox_api.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_outbound_kerberos_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_outbound_mobsync_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_outbound_smtp_connections.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_prog_location_network_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_susp_rdp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/network_connection/net_connection_win_wuauclt_network_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_alternate_powershell_hosts_pipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_apt_turla_namedpipes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_cred_dump_tools_named_pipes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_efspotato_namedpipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_mal_cobaltstrike.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_mal_cobaltstrike_re.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_mal_namedpipes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_powershell_execution_pipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_psexec_pipes_artifacts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_susp_adfs_namedpipe_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_susp_cobaltstrike_pipe_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_susp_wmi_consumer_namedpipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/pipe_created/pipe_created_tool_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_alternate_powershell_hosts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_delete_volume_shadow_copies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_downgrade_attack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_exe_calling_ps.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_powercat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_remote_powershell_session.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_renamed_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_susp_athremotefxvgpudisablementcommand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_susp_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_susp_get_nettcpconnection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_susp_zip_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_tamper_with_windows_defender.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_wsman_com_provider_no_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_classic/posh_pc_xor_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_alternate_powershell_hosts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_bad_opsec_artifacts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_clear_powershell_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_decompress_commands.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_get_addbaccount.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_get_clipboard.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_obfuscated_iex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_rundll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_use_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_use_mhsta.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_use_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_invoke_obfuscation_via_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_powercat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_remote_powershell_session.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_ad_group_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_athremotefxvgpudisablementcommand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_get_nettcpconnection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_invocation_generic.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_invocation_specific.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_reset_computermachinepassword.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_smb_share_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_susp_zip_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_module/posh_pm_syncappvpublishingserver_exe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_access_to_browser_login_data.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_accessing_win_api.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_adrecon_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_as_rep_roasting.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_automated_collection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_azurehound_commands.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_capture_screenshots.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cl_invocation_lolscript_count.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cl_mutexverifiers_lolscript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cl_mutexverifiers_lolscript_count.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_clear_powershell_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_clearing_windows_console_history.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cmdlet_scheduled_task.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_copy_item_system32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_cor_profiler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_create_local_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_create_volume_shadow_copy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_data_compressed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_detect_vm_env.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_directorysearcher.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_directoryservices_accountmanagement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_dnscat_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_dump_password_windows_credential_manager.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_enable_psremoting.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_enumerate_password_windows_credential_manager.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_etw_trace_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_file_and_directory_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_get_acl_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_get_adreplaccount.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_get_childitem_bookmarks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_hotfix_enum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_icmp_exfiltration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_command_remote.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_nightmare.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_obfuscated_iex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_rundll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_use_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_use_mhsta.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_use_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_invoke_obfuscation_via_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_keylogging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_localuser.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_malicious_commandlets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_malicious_keywords.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_memorydump_getstoragediagnosticinfo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_msxml_com.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_nishang_malicious_commandlets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_ntfs_ads_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_office_comobject_registerxll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_powerview_malicious_commandlets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_prompt_credentials.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_psattack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_remote_session_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_remove_item_path.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_request_kerberos_ticket.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_root_certificate_installed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_run_from_mount_diskimage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_security_software_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_send_mailmessage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_set_policies_to_unsecure_level.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_shellcode_b64.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_shellintel_malicious_commandlets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_software_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_store_file_in_alternate_data_stream.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_ad_group_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_directory_enum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_execute_batch_script.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_export_pfxcertificate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_extracting.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_follina_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_adcomputer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_addefaultdomainpasswordpolicy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_adgroup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_current_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_gpo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_get_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_getprocess_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_gettypefromclsid.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_gwmi.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_hyper_v_condlet.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_invocation_generic.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_invocation_specific.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_invoke_webrequest_useragent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_iofilestream.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_keywords.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_local_group_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_mail_acces.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_mount_diskimage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_mounted_share_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_networkcredential.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_new_psdrive.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_recon_export.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_remove_adgroupmember.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_smb_share_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_ssl_keyword.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_start_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_unblock_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_wallpaper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_win32_pnpentity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_win32_shadowcopy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_windowstyle.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_susp_zip_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_syncappvpublishingserver_exe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_tamper_defender.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_test_netconnection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_timestomp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_trigger_profiles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_upload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_web_request.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_win32_product_install_msi.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_windows_firewall_profile_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_winlogon_helper_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_wmimplant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/powershell/powershell_script/posh_ps_xml_iex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_cmstp_execution_by_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_cobaltstrike_bof_injection_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_cred_dump_lsass_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_direct_syscall_ntopenprocess.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_handlekatz_lsass_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_in_memory_assembly_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_invoke_phantom.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lazagne_cred_dump_lsass_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_littlecorporal_generated_maldoc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_load_undocumented_autoelevated_com_interface.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lsass_dump_comsvcs_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lsass_memdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lsass_memdump_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lsass_memdump_indicators.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_lsass_werfault.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_malware_verclsid_shellcode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_mimikatz_trough_winrm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_pypykatz_cred_dump_lsass_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_rare_proc_access_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_susp_proc_access_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_susp_proc_access_lsass_susp_source.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_svchost_cred_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/proc_access_win_uac_bypass_wow64_logger.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/process_access_win_shellcode_inject_msf_empire.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_access/process_access_win_susp_seclogon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_7zip_cve_2022_29072.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_abusing_debug_privilege.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_abusing_windows_telemetry_for_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_accesschk_usage_after_priv_escalation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_ad_find_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_advanced_ip_scanner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_advanced_port_scanner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_alternate_data_streams.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_always_install_elevated_msi_spawned_cmd_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_always_install_elevated_windows_installer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_anydesk.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_anydesk_silent_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_anydesk_susp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_actinium_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_apt29_thinktanks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_babyshark.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_bear_activity_gtr19.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_bluemashroom.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_chafer_mar18.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_cloudhopper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_dragonfly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_elise.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_emissarypanda_sep19.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_empiremonkey.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_equationgroup_dll_u_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_evilnum_jul20.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_gallium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_gallium_sha1.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_gamaredon_ultravnc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_greenbug_may20.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_hafnium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_hurricane_panda.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_judgement_panda_gtr19.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_ke3chang_regadd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_lazarus_activity_apr21.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_lazarus_activity_dec20.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_lazarus_loader.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_lazarus_session_highjack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_muddywater_dnstunnel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_mustangpanda.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_revil_kaseya.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_slingshot.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_sofacy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_sourgrum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_ta17_293a_ps.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_ta505_dropper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_taidoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_tropictrooper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_turla_commands_critical.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_turla_commands_medium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_turla_comrat_may20.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_unc2452_cmds.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_unc2452_ps.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_unidentified_nov_18.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_winnti_mal_hk_jan20.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_winnti_pipemon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_wocao.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_apt_zxshell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_arbitrary_shell_execution_via_settingcontent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_archiver_iso_phishing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_asr_bypass_via_appvlp_re.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_atlassian_confluence_cve_2021_26084_exploit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_attrib_hiding_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_attrib_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_attrib_system_susp_paths.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_automated_collection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bad_opsec_sacrificial_processes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_base64_invoke_susp_cmdlets.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_base64_listing_shadowcopy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_base64_reflective_assembly_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_domain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_ext.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_ip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bitsadmin_download_uncommon_targetfolder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bootconf_mod.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_bypass_squiblytwo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_c3_load_by_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_certoc_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_change_default_file_assoc_susp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_change_default_file_association.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_chrome_load_extension.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cleanwipe.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmd_delete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmd_dosfuscation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmd_redirect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmstp_com_object_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cmstp_execution_by_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cobaltstrike_bloopers_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cobaltstrike_bloopers_modules.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cobaltstrike_load_by_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cobaltstrike_process_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_commandline_path_traversal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_commandline_path_traversal_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_conhost_path_traversal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_conti_cmd_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_conti_sqlcmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_control_panel_item.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_copying_sensitive_files_with_credential_data.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_crackmapexec_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_creation_mavinject_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_creative_cloud_node_abuse.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_credential_access_via_password_filter.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_crime_fireball.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_crime_maze_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_crime_snatch_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_crypto_mining_monero.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_curl_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_cve_2021_26857_msexchange.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_data_compressed_with_rar.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_delete_systemstatebackup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_detecting_fake_instances_of_hxtsr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dinjector.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_discover_private_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dns_exfiltration_tools_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dns_serverlevelplugindll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dnscat2_powershell_implementation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dotnet.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dsacls_abuse_permissions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dsacls_password_spray.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dsim_remove.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_dumpstack_log_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_embed_exe_lnk.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_encoded_frombase64string.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_encoded_iex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_enumeration_for_credentials_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_enumeration_for_credentials_in_registry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_esentutl_webcache.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_etw_modification_cmdline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_etw_trace_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_evil_winrm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exfiltration_and_tunneling_tools_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_expand_cabinet_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2015_1641.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2017_0261.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2017_11882.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2017_8759.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2019_1378.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2019_1388.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2020_10189.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2020_1048.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_cve_2020_1350.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_lpe_cve_2021_41379.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_exploit_systemnightmare.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_false_sysinternalsuite.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_file_permission_modifications.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_findstr_gpp_passwords.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_fsutil_drive_enumeration.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_fsutil_symlinkevaluation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_gotoopener.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_grabbing_sensitive_hives_via_reg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_adcspwn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_bloodhound.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_cube0x0_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_dumpert.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_hydra.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_koadic.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_krbrelay.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_krbrelayup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_rubeus.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_secutyxploded.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hack_wce.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hacktool_imphashes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hashcat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_headless_browser_file_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hh_chm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hiding_malware_in_fonts_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_high_integrity_sdclt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hktl_createminidump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hktl_uacme_uac_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_html_help_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_hwp_exploits.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_iis_http_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_impacket_compiled_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_impacket_lateralization.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_indirect_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_infdefaultinstall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_install_reg_debugger_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_interactive_at.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_obfuscated_iex_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_rundll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_stdin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_use_clip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_use_mhsta.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_use_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_invoke_obfuscation_via_var.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_jlaive_batch_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lethalhta.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_local_system_owner_account_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_logmein.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_logon_scripts_userinitmprlogonscript_proc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_adplus.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_aspnet_compiler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_bash.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_certoc_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_cl_invocation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_cl_loadassembly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_cl_mutexverifiers.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_class_exec_xwizard.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_cmdl32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_configsecuritypolicy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_cscript_gathernetworkinfo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_data_exfiltration_by_using_datasvcutil.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_diantz_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_dll_sideload_xwizard.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_dump64.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_execution_via_winget.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_extexport.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_extrac32_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_findstr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_fsharp_interpreters.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_gpscript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_ie4uinit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_ieexec_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_ilasm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_jsc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_mftrace.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_msdt_answer_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_offlinescannershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_openconsole.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_pcalua.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_pcwrun_follina.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_pktmon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_presentationhost.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_pubprn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_rasautou_dll_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_remote.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_replace.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_rundll32_installscreensaver.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_scriptrunner.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_squirrel.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_acccheckconsole.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_atbroker.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_certreq_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_driver_installed_by_pnputil.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_dxcap.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_grpconv.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_mpcmdrun_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_sqldumper_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_susp_wsl.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_execute_psh.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_syncappvpublishingserver_vbs_execute_psh.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_ttdinject.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_tttracer_mod_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_utilityfunctions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_visual_basic_compiler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_visualuiaverifynative.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_vsiisexelauncher.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_wfc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_winword.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbin_wlrmdr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbins_by_office_applications.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lolbins_with_wmiprvse_parent_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_long_powershell_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_lsass_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mailboxexport_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_adwind.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_blue_mockingbird.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_darkside_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_hermetic_wiper_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_lockergoga_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mal_ryuk.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_conti.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_conti_7zip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_conti_shadowcopy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_dridex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_dtrack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_emotet.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_formbook.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_notpetya.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_qbot.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_ryuk.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_script_dropper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_trickbot_recon_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_trickbot_wermgr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_malware_wannacry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_manage_bde_lolbas.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mavinject_proc_inj.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_meterpreter_or_cobaltstrike_getsystem_service_start.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mimikatz_command_line.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mmc20_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mmc_spawn_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_modif_of_services_for_via_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_monitoring_for_persistence_via_bits.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mouse_lock.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msdeploy.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msdt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msdt_diagcab.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msdt_susp_cab_options.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msdt_susp_parent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msedge_minimized_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mshta_spawn_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msiexec_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msiexec_embedding.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msiexec_execute_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msiexec_install_quiet.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_msra_process_injection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_mstsc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_multiple_susp_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_net_enum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_net_use_admin_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_net_user_add.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netcat_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_allow_port_rdp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_fw_add.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_fw_add_susp_image.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_fw_enable_group_rule.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_packet_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_port_fwd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_port_fwd_3389.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_netsh_wifi_credential_harvesting.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_network_scan_loop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_network_sniffing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_new_service_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_nltest_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_non_interactive_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_non_priv_reg_or_ps.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_applications_spawning_wmi_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_dir_traversal_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_from_proxy_executing_regsvr32_payload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_from_proxy_executing_regsvr32_payload2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_spawn_exe_from_users_directory.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_office_spawning_wmi_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_outlook_shell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_pingback_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_plugx_susp_exe_locations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_possible_applocker_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_possible_privilege_escalation_via_service_reg_perm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_amsi_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_b64_shellcode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_bitsjob.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_cmdline_reversed_strings.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_cmdline_special_characters.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_cmdline_specific_comb_methods.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_defender_base64.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_defender_disable_feature.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_defender_exclusion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_disable_windef_av.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_dll_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_downgrade_attack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_download_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_frombase64string.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_get_clipboard.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_public_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_reverse_shell_connection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_snapins_hafnium.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_susp_parameter_variation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powershell_xor_commandline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_powersploit_empire_schtasks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proc_dump_createdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proc_dump_dumpminitool.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proc_dump_rdrleakdiag.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proc_dump_susp_dumpminitool.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proc_wrong_parent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_procdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_procdump_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_process_dump_rdrleakdiag.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_process_dump_rundll32_comsvcs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_protocolhandler_susp_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_proxy_execution_wuauclt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_psexesvc_start.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_public_folder_parent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_purplesharp_indicators.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_pypykatz.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_python_pty_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_query_registry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_ransom_blackbyte.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rdp_hijack_shadowing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_redirect_to_stream.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_redmimicry_winnti_proc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_add_run_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_defender_exclusion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_defender_tampering.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_dump_sam.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_enable_rdp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_lsass_ppl.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_reg_service_imagepath_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regedit_export_critical_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regedit_export_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regedit_import_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regedit_import_keys_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regini.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_regini_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_remote_powershell_session_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_remote_time_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_remove_windows_defender_definition_files.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_binary.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_browsercore.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_jusched.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_megasync.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_msdt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_paexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_plink.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_procdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_renamed_whoami.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_root_certificate_installed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rpcss_anomalies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_run_executable_invalid_extension.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_run_from_zip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_run_powershell_script_from_ads.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_run_powershell_script_from_input_stream.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_run_virtualbox.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rundll32_not_from_c_drive.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rundll32_parent_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rundll32_registered_com_objects.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_rundll32_without_parameters.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_schtasks_appdata_local_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_schtasks_powershell_windowsapps_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_schtasks_reg_loader.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_screenconnect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_screenconnect_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_script_event_consumer_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sdbinst_shim_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sdclt_child_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sdelete.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sdiagnhost_susp_child.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_service_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_service_stop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_set_policies_to_unsecure_level.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_shadow_copies_access_symlink.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_shadow_copies_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_shadow_copies_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_shell_spawn_by_java.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_shell_spawn_susp_program.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_silenttrinity_stage_use.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_software_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_soundrec_audio_capture.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_spn_enum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sqlcmd_veeam_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sqlite_firefox_cookies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sticky_keys_unauthenticated_privileged_cmd_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_stickykey_like_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_stordiag_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sus_auditpol_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_7z.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ad_reco.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_add_user_remote_desktop.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_adfind.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_adfind_enumerate.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_adidnsdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_advancedrun.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_advancedrun_priv_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_athremotefxvgpudisablementcommand.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_base64_invoke.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_base64_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_bcdedit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_bginfo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_bitstransfer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_calc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cdb.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_certutil_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_certutil_encode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_char_in_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_child_process_as_system_.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cipher.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cli_escape.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cmd_http_appdata.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cmd_shadowcopy_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_codepage_lookup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_codepage_switch.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_commandline_chars.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_commands_recon_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_compression_params.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_comsvcs_procdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_conhost.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_conhost_option.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_control_cve_2021_40444.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_control_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_copy_lateral_movement.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_copy_system32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_covenant.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_crackmapexec_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_crackmapexec_flags.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_crackmapexec_powershell_obfuscation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_csc.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_csc_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_cscript_vbs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_csi.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_curl_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_curl_fileupload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_curl_start_combo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_curl_useragent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_dctask64_proc_inject.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_del.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_desktopimgdownldr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_devinit_lolbin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_devtoolslauncher.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_dir.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_direct_asep_reg_keys_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_disable_eventlog.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_disable_ie_features.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_disable_raccine.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_diskshadow.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ditsnap.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_dllhost_no_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_dnx.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_double_extension.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_download_office_domain.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_dtrace_kernel_dump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_emotet_rundll32_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_esentutl_params.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_eventlog_clear.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_execution_path.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_execution_path_webserver.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_explorer_break_proctree.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_explorer_nouaccheck.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_file_characteristics.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_file_download_via_gfxdownloadwrapper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_findstr_385201.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_findstr_lnk.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_finger_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_firewall_disable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_format.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_fsutil_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ftp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_gpresult.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_gup.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_gup_download.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_gup_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_hostname.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_image_missing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_instalutil.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_iss_module_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_lsass_clone.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_machineguid.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_mounted_share_deletion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_mpiexec_lolbin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_mshta_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_mshta_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_msiexec_cwd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_msiexec_web_install.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_msoffice.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_net_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_net_use_password_plaintext.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_netsh_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_netsh_dll_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_network_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_network_listing_connections.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ngrok_pua.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_nmap.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_non_exe_image.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_nt_resource_kit_auditpol_usage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ntdll_type_redirect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ntds.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ntdsutil.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ntlmrelay.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_odbcconf.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_openwith.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_outlook.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_outlook_temp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_parents.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_pcwutl.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_pester.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ping_hex_ip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_plink_remote_forward.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_cmd_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_download_cradles.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_download_iex.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_empire_launch.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_empire_uac_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_enc_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_encode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_encoded_param.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_getprocess_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_hidden_b64_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_iex_patterns.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_parent_combo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_parent_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_sam_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_sub_processes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_powershell_webclient_casing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_pressynkey_lolbin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_print.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_procdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_procdump_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_progname.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ps_appdata.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_ps_downloadfile.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_psexec_eula.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_psexex_paexec_escalate_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_psexex_paexec_flags.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_psloglist.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_psr_capture_screenshots.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_radmin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rar_flags.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rasdial_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_razorinstaller_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rclone_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_recon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_recon_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_recon_net_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_redir_local_admin_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_reg_bitlocker.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_reg_disable_sec_services.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_reg_open_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regedit_trustedinstaller.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_register_cimprovider.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_registration_via_cscript.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_anomalies.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_flags_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_http_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_image.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_regsvr32_no_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_renamed_dctask64.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_renamed_debugview.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_renamed_paexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rpcping.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_run_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_run_locations.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_activity.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_by_ordinal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_inline_vbs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_js_runhtmlapplication.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_keymgr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_no_params.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_script_run.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_setupapi_installhinfsection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_spawn_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_sys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_rundll32_user32_dll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_runonce_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_runscripthelper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_sc_query.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtask_creation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtask_creation_temp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_disable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_env_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_folder_combos.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_parent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_schtasks_user_temp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_screenconnect_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_screensaver_reg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_script_exec_from_env_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_script_exec_from_temp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_script_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_service_dacl_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_service_dir.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_service_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_service_path_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_servu_exploitation_cve_2021_35211.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_servu_process_pattern.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_sharpview.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_by_java.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_by_java_keytool.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_from_mssql.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_from_winrm.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shimcache_flush.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_shutdown.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_splwow64.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_spoolsv_child_processes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_squirrel_lolbin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_svchost.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_svchost_no_cli.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_sysprep_appdata.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_system_user_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_systeminfo.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_sysvol_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_takeown.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_target_location_shell32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_taskkill.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_tasklist_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_taskmgr_localsystem.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_taskmgr_parent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_tracker_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_trolleyexpress_procdump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_tscon_localsystem.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_tscon_rdp_redirect.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_uac_bypass_trustedpath.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_use_of_csharp_console.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_use_of_sqlps_bin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_use_of_sqltoolsps_bin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_use_of_te_bin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_use_of_vsjitdebugger_bin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_userinit_child.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_vaultcmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_vboxdrvinst.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_vbscript_unc2452.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_volsnap_disable.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_web_request_cmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_webdav_client_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_where_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_whoami.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_whoami_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_whoami_as_param.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_winrar_dmp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_winrar_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_winrm_awl_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_winrm_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_winzip.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wmi_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wmic_eventconsumer_create.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wmic_proc_create_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wmic_security_product_uninstall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_workfolders.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wuauclt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_wuauclt_cmdline.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_zip_compress.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_susp_zipexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sysinternals_eula_accepted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sysinternals_psservice.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sysmon_driver_unload.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_sysmon_uac_bypass_eventvwr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_system_exe_anomaly.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tap_installer_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_task_folder_evasion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_termserv_proc_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tool_nircmd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tool_nircmd_as_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tool_nsudo_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tool_psexec.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tool_runx_as_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tools_relay_attacks.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_tor_browser.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_trust_discovery.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_changepk_slui.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_cleanmgr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_computerdefaults.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_consent_comctl32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_dismhost.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_fodhelper.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_idiagnostic_profile.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_ieinstal.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_msconfig_gui.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_ntfs_reparse_point.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_pkgmgr_dism.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_winsat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_wmp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset_integrity_level.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uninstall_crowdstrike_falcon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_uninstall_sysmon.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_using_sc_to_change_sevice_image_path_by_non_admin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_using_sc_to_hide_sevices.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_using_settingsynchost_as_lolbin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_verclsid_runs_com.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_vmtoolsd_susp_child_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_vul_java_remote_debugging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_webshell_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_webshell_hacking.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_webshell_recon_detection.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_webshell_spawn.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_whoami_as_priv_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_whoami_as_system.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_whoami_priv.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_win10_sched_task_0day.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_win_exchange_transportagent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_winword_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmi_backdoor_exchange_transport_agent.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmi_persistence_script_event_consumer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmi_spwns_powershell.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_hotfix_enum.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_reconnaissance.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_remote_command.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_remote_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_remove_application.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmic_unquoted_service_search.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wmiprvse_spawning_process.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_workflow_compiler.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_write_protect_for_storage_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_wsreset_uac_bypass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_xordump.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/process_creation/proc_creation_win_xsl_script_processing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/raw_access_thread/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/raw_access_thread/sysmon_raw_disk_access_using_illegitimate_tools.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_logon_scripts_userinitmprlogonscript_reg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_mal_netwire.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_mal_ursnif.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_persistence_key_linking.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_sysinternals_eula_accepted.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_add/registry_add_sysinternals_sdelete_registry_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_delete/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_delete/registry_delete_mstsc_history_cleared.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_delete/registry_delete_removal_amsi_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_delete/registry_delete_removal_com_hijacking_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_delete/registry_delete_removal_sd_value_scheduled_task_hide.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_add_local_hidden_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_apt_chafer_mar18.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_apt_leviathan.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_apt_oceanlotus_registry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_apt_pandemic.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_bypass_via_wsreset.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_cmstp_execution_by_registry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_crashdump_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_cve_2021_31979_cve_2021_33771_exploits.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_disable_security_events_logging_adding_reg_key_minint.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_disable_wdigest_credential_guard.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_dns_serverlevelplugindll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_esentutl_volume_shadow_copy_service_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_hack_wce_reg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_hybridconnectionmgr_svc_installation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_mal_azorult.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_mal_flowcloud.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_mimikatz_printernightmare.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_modify_screensaver_binary_path.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_narrator_feedback_persistance.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_net_ntlm_downgrade.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_new_dll_added_to_appcertdlls_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_new_dll_added_to_appinit_dlls_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_office_test_regadd.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_persistence_recycle_bin.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_portproxy_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_redmimicry_winnti_reg.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_runkey_winekey.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_runonce_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_shell_open_keys_manipulation.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_silentprocessexit_lsass.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_ssp_added_lsa_config.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_stickykey_like_backdoor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_susp_atbroker_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_susp_download_run_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_susp_lsass_dll_load.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_susp_mic_cam_access.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_event/registry_event_trust_record_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_abusing_windows_telemetry_for_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_add_load_service_in_safe_mode.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_add_port_monitor.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_classes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_common.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentcontrolset.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentversion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_currentversion_nt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_internet_explorer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_office.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_session_manager.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_system_scripts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_winsock2.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_wow6432node.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_wow6432node_classes.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_asep_reg_keys_modification_wow6432node_currentversion.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_blackbyte_ransomware.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_bypass_uac_using_delegateexecute.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_bypass_uac_using_eventviewer.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_bypass_uac_using_silentcleanup_task.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_change_rdp_port.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_change_security_zones.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_chrome_extension.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_cobaltstrike_service_installs.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_comhijack_sdclt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_creation_service_susp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_creation_service_temp_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_creation_service_uncommon_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_custom_file_open_handler_powershell_execution.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_cve_2020_1048_new_printer_port.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_cve_2022_30190_msdt_follina.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_defender_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_defender_exclusions.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_defender_realtime_protection_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_dhcp_calloutdll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_administrative_share.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_defender_firewall.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_fonction_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_microsoft_office_security_features.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_system_restore.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_uac_registry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disable_winevt_logging.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disabled_exploit_guard_net_protection_on_ms_defender.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disabled_microsoft_defender_eventlog.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disabled_pua_protection_on_microsoft_defender.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_disabled_tamper_protection_on_microsoft_defender.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_dns_over_https_enabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_enabling_cor_profiler_env_variables.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_enabling_turnoffcheck.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_etw_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_file_association_exefile.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_globalflags_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_hidden_extention.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_hide_file.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_hide_fonction_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_ie_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_install_root_or_ca_certificat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_mal_adwind.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_mal_blue_mockingbird.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_new_application_appcompat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_office_enable_dde.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_office_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_office_vsto_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_outlook_c2_registry_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_outlook_registry_todaypage.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_outlook_registry_webview.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_outlook_security.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_persistence_search_order.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_powershell_as_service.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_powershell_in_run_keys.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_powershell_logging_disabled.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_rdp_registry_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_rdp_settings_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_scr_file_executed_by_rundll32.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_set_nopolicies_user.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_set_servicedll.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_shim_databases_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_silentprocessexit.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_susp_printer_driver.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_susp_reg_persist_explorer_run.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_susp_run_key_img_folder.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_susp_service_installed.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_taskcache_entry.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_telemetry_persistence.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_timeproviders_dllname.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_uac_bypass_eventvwr.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_uac_bypass_sdclt.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_uac_bypass_winsat.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_uac_bypass_wmp.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_vbs_payload_stored.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_wab_dllpath_reg_change.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_wdigest_enable_uselogoncredential.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/registry/registry_set/registry_set_winlogon_notify_key.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_accessing_winapi_in_powershell_credentials_dumping.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_config_modification.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_config_modification_error.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_config_modification_status.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_dcom_iertutil_dll_hijack.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/sysmon/sysmon_process_hollowing.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/wmi_event/
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/wmi_event/sysmon_wmi_event_subscription.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/wmi_event/sysmon_wmi_susp_encoded_scripts.yml
- /usr/local/opensearch/opensearch-security-analytics/rules/windows/wmi_event/sysmon_wmi_susp_scripting.yml
- /usr/local/opensearch/plugins/
- /usr/local/opensearch/plugins/opensearch-alerting/
- /usr/local/opensearch/plugins/opensearch-alerting/alerting-core-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/alerting-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/annotations-13.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/commons-codec-1.13.jar
- /usr/local/opensearch/plugins/opensearch-alerting/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-alerting/commons-validator-1.7.jar
- /usr/local/opensearch/plugins/opensearch-alerting/cron-utils-9.1.7.jar
- /usr/local/opensearch/plugins/opensearch-alerting/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-alerting/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-alerting/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-alerting/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-alerting/ipaddress-5.4.1.jar
- /usr/local/opensearch/plugins/opensearch-alerting/json-20240303.jar
- /usr/local/opensearch/plugins/opensearch-alerting/kotlin-stdlib-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/kotlin-stdlib-jdk8-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/kotlinx-coroutines-core-1.1.1.jar
- /usr/local/opensearch/plugins/opensearch-alerting/opensearch-alerting-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/opensearch-sql-thin-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/percolator-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-alerting/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-alerting/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-alerting/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/commons-codec-1.18.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/commons-math3-3.6.1.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/commons-pool2-2.12.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/encoder-1.3.1.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/failureaccess-1.0.3.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/gson-2.11.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/guava-33.4.5-jre.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/memory-0.12.2.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/opensearch-anomaly-detection-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/org.jacoco.agent-0.8.13.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/org.jacoco.ant-0.8.13.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/protostuff-api-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/protostuff-collectionschema-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/protostuff-core-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/protostuff-runtime-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/randomcutforest-core-4.4.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/randomcutforest-parkservices-4.4.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/randomcutforest-serialization-4.4.0.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/sketches-core-0.13.4.jar
- /usr/local/opensearch/plugins/opensearch-anomaly-detection/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-asynchronous-search/
- /usr/local/opensearch/plugins/opensearch-asynchronous-search/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-asynchronous-search/opensearch-asynchronous-search-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-asynchronous-search/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-asynchronous-search/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/annotations-13.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/ipaddress-5.4.1.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/kotlin-stdlib-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/kotlin-stdlib-jdk7-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/kotlin-stdlib-jdk8-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/kotlinx-coroutines-core-jvm-1.6.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/opensearch-cross-cluster-replication-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-cross-cluster-replication/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-custom-codecs/
- /usr/local/opensearch/plugins/opensearch-custom-codecs/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-custom-codecs/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-custom-codecs/opensearch-custom-codecs-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-custom-codecs/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-custom-codecs/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-custom-codecs/qat-java-2.3.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/
- /usr/local/opensearch/plugins/opensearch-flow-framework/DafnyRuntime-4.11.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-flow-framework/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-flow-framework/aws-cryptographic-material-providers-1.11.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/aws-encryption-sdk-java-3.0.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/bc-fips-2.1.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/commons-codec-1.18.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/commons-text-1.14.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/conversion-0.1.1.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/gson-2.13.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/jackson-datatype-jsr310-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/jakarta.json-2.0.1.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/jakarta.json.bind-api-3.0.1.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/json-20231013.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/json-path-2.10.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/opensearch-flow-framework-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/opensearch-ml-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/opensearch-remote-metadata-sdk-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-flow-framework/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-flow-framework/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/swagger-core-2.2.41.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/swagger-models-2.2.41.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/swagger-parser-2.1.36.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/swagger-parser-core-2.1.36.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/swagger-parser-v3-2.1.36.jar
- /usr/local/opensearch/plugins/opensearch-flow-framework/yasson-3.0.4.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/
- /usr/local/opensearch/plugins/opensearch-geospatial/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-geospatial/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-geospatial/commons-csv-1.10.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/geo-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/geospatial-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/h3-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/ipaddress-5.4.2.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/opensearch-geospatial-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-geospatial/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-geospatial/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-index-management/
- /usr/local/opensearch/plugins/opensearch-index-management/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-index-management/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-index-management/annotations-23.0.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/commons-codec-1.17.2.jar
- /usr/local/opensearch/plugins/opensearch-index-management/httpclient-4.5.14.jar
- /usr/local/opensearch/plugins/opensearch-index-management/httpcore-4.4.16.jar
- /usr/local/opensearch/plugins/opensearch-index-management/ipaddress-5.5.1.jar
- /usr/local/opensearch/plugins/opensearch-index-management/kotlin-stdlib-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/kotlin-stdlib-jdk7-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/kotlinx-coroutines-core-jvm-1.7.3.jar
- /usr/local/opensearch/plugins/opensearch-index-management/opensearch-index-management-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/opensearch-index-management-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-index-management/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-index-management/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-job-scheduler/
- /usr/local/opensearch/plugins/opensearch-job-scheduler/opensearch-job-scheduler-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-job-scheduler/opensearch-job-scheduler-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-job-scheduler/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-knn/
- /usr/local/opensearch/plugins/opensearch-knn/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-knn/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-knn/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-knn/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-knn/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-knn/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-knn/jna-platform-5.16.0.jar
- /usr/local/opensearch/plugins/opensearch-knn/lib/
- /usr/local/opensearch/plugins/opensearch-knn/lib/libgomp.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libgomp.so.1
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_common.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_faiss.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_faiss_avx2.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_faiss_avx512.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_faiss_avx512_spr.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_nmslib.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_simd.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_simd_avx2.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_simd_avx512.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_simd_avx512_spr.so
- /usr/local/opensearch/plugins/opensearch-knn/lib/libopensearchknn_util.so
- /usr/local/opensearch/plugins/opensearch-knn/opensearch-knn-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-knn/oshi-core-6.4.13.jar
- /usr/local/opensearch/plugins/opensearch-knn/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-knn/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-knn/remote-index-build-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-knn/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-ltr/
- /usr/local/opensearch/plugins/opensearch-ltr/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-ltr/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-ltr/RankyMcRankFace-0.1.1.jar
- /usr/local/opensearch/plugins/opensearch-ltr/antlr4-runtime-4.11.1.jar
- /usr/local/opensearch/plugins/opensearch-ltr/asm-9.6.jar
- /usr/local/opensearch/plugins/opensearch-ltr/asm-commons-9.6.jar
- /usr/local/opensearch/plugins/opensearch-ltr/asm-tree-9.6.jar
- /usr/local/opensearch/plugins/opensearch-ltr/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ltr/compiler-0.9.3.jar
- /usr/local/opensearch/plugins/opensearch-ltr/conscrypt-openjdk-uber-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-ltr/lucene-expressions-9.7.0.jar
- /usr/local/opensearch/plugins/opensearch-ltr/opensearch-ltr-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ltr/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-ltr/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-ltr/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-ml/
- /usr/local/opensearch/plugins/opensearch-ml/DafnyRuntime-4.9.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/accessors-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/annotations-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/apache-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/api-0.31.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/asm-9.7.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/auth-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-cryptographic-material-providers-1.11.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-database-encryption-sdk-dynamodb-3.9.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-encryption-sdk-java-2.4.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-java-sdk-core-1.12.780.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-java-sdk-dynamodb-1.12.780.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-java-sdk-kms-1.12.780.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-java-sdk-s3-1.12.780.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-json-protocol-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-query-protocol-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/aws-xml-protocol-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/bc-fips-2.1.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/bedrockruntime-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/checker-qual-3.37.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/checksums-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/checksums-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-beanutils-1.11.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-codec-1.15.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-collections-3.2.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-collections4-4.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-compress-1.26.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-io-2.15.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-logging-1.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-math3-3.6.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/commons-text-1.14.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/conversion-0.1.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/dynamodb-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/dynamodb-enhanced-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/endpoints-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/eventstream-1.0.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/gson-2.13.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/guava-32.1.3-jre.jar
- /usr/local/opensearch/plugins/opensearch-ml/http-auth-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/http-auth-aws-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/http-auth-aws-eventstream-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/http-auth-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/http-client-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpclient-4.5.14.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpcore-4.4.15.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/identity-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/itu-1.10.3.jar
- /usr/local/opensearch/plugins/opensearch-ml/jackson-annotations-2.18.3.jar
- /usr/local/opensearch/plugins/opensearch-ml/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/jackson-datatype-jsr310-2.18.3.jar
- /usr/local/opensearch/plugins/opensearch-ml/jakarta.json-2.0.0-module.jar
- /usr/local/opensearch/plugins/opensearch-ml/jakarta.json-api-2.1.3.jar
- /usr/local/opensearch/plugins/opensearch-ml/jakarta.json.bind-api-2.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jansi-2.4.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/javassist-3.26.0-GA.jar
- /usr/local/opensearch/plugins/opensearch-ml/jline-builtins-3.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jline-reader-3.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jline-style-3.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jline-terminal-3.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jline-terminal-jansi-3.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/jmespath-java-1.12.780.jar
- /usr/local/opensearch/plugins/opensearch-ml/json-20231013.jar
- /usr/local/opensearch/plugins/opensearch-ml/json-path-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/json-schema-validator-1.5.7.jar
- /usr/local/opensearch/plugins/opensearch-ml/json-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/json-utils-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/jsr305-3.0.2.jar
- /usr/local/opensearch/plugins/opensearch-ml/kms-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/kotlin-stdlib-1.9.23.jar
- /usr/local/opensearch/plugins/opensearch-ml/kotlin-stdlib-jdk7-1.9.10.jar
- /usr/local/opensearch/plugins/opensearch-ml/kotlin-stdlib-jdk8-1.9.10.jar
- /usr/local/opensearch/plugins/opensearch-ml/libsvm-3.25.jar
- /usr/local/opensearch/plugins/opensearch-ml/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
- /usr/local/opensearch/plugins/opensearch-ml/log4j-slf4j-impl-2.21.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/mcp-0.12.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/metrics-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-buffer-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-base-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-compression-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-http-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-http2-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-marshalling-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-codec-protobuf-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-handler-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-nio-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-resolver-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-transport-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-transport-classes-epoll-4.1.124.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/netty-transport-native-unix-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-ml/okhttp-4.12.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/okhttp-sse-4.12.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/okio-jvm-3.6.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/olcut-config-protobuf-5.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/olcut-core-5.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/onnxruntime-engine-0.31.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/onnxruntime_gpu-1.16.3.jar
- /usr/local/opensearch/plugins/opensearch-ml/opencsv-5.4.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-java-3.3.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-algorithms-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-common-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-memory-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-search-processors-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-ml-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-remote-metadata-sdk-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-remote-metadata-sdk-aos-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-remote-metadata-sdk-ddb-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-remote-metadata-sdk-remote-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/parsson-1.1.7.jar
- /usr/local/opensearch/plugins/opensearch-ml/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-ml/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-ml/profiles-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/protocol-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/protostuff-api-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/protostuff-collectionschema-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/protostuff-core-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/protostuff-runtime-1.8.0.jar
- /usr/local/opensearch/plugins/opensearch-ml/pytorch-engine-0.31.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/pytorch-model-zoo-0.31.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/randomcutforest-core-3.0-rc3.jar
- /usr/local/opensearch/plugins/opensearch-ml/randomcutforest-parkservices-3.0-rc3.jar
- /usr/local/opensearch/plugins/opensearch-ml/randomcutforest-testutils-3.0-rc3.jar
- /usr/local/opensearch/plugins/opensearch-ml/reflections-0.9.12.jar
- /usr/local/opensearch/plugins/opensearch-ml/regions-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/retries-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/retries-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/s3-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/sdk-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/slf4j-api-1.7.36.jar
- /usr/local/opensearch/plugins/opensearch-ml/sts-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/third-party-jackson-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/tokenizers-0.31.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-anomaly-core-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-anomaly-libsvm-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-classification-core-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-classification-sgd-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-clustering-core-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-clustering-kmeans-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-common-libsvm-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-common-sgd-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-common-tree-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-core-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-data-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-math-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-regression-core-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-regression-sgd-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-util-infotheory-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-util-onnx-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/tribuo-util-tokenization-4.2.1.jar
- /usr/local/opensearch/plugins/opensearch-ml/url-connection-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/utils-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-ml/yasson-2.0.2.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/
- /usr/local/opensearch/plugins/opensearch-neural-search/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-neural-search/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-neural-search/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/commons-collections4-4.5.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/commons-math3-3.6.1.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/commons-text-1.10.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/gson-2.10.1.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/javassist-3.29.2-GA.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/json-20231013.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/json-path-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/json-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/mapper-extras-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/opensearch-ml-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/opensearch-neural-search-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-neural-search/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-neural-search/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-neural-search/reflections-0.9.12.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/
- /usr/local/opensearch/plugins/opensearch-notifications-core/angus-activation-2.0.2.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/angus-mail-2.0.4.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/aws-java-sdk-core-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/aws-java-sdk-ses-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/aws-java-sdk-sns-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/aws-java-sdk-sts-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/jakarta.activation-api-2.1.3.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/jakarta.mail-api-2.1.3.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/kotlin-stdlib-2.2.20.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/log4j-slf4j-impl-2.21.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/opensearch-notifications-core-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/opensearch-notifications-core-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications-core/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-notifications-core/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-notifications-core/slf4j-api-2.0.17.jar
- /usr/local/opensearch/plugins/opensearch-notifications/
- /usr/local/opensearch/plugins/opensearch-notifications/DafnyRuntime-4.9.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/annotations-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/apache-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/auth-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-cryptographic-material-providers-1.11.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-database-encryption-sdk-dynamodb-3.9.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-java-sdk-dynamodb-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-java-sdk-kms-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-java-sdk-s3-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-json-protocol-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/aws-query-protocol-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/bcprov-jdk18on-1.78.1.jar
- /usr/local/opensearch/plugins/opensearch-notifications/checksums-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/checksums-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/conversion-0.1.1.jar
- /usr/local/opensearch/plugins/opensearch-notifications/dynamodb-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/dynamodb-enhanced-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/endpoints-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/eventstream-1.0.1.jar
- /usr/local/opensearch/plugins/opensearch-notifications/http-auth-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/http-auth-aws-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/http-auth-aws-eventstream-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/http-auth-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/http-client-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/httpclient-4.5.14.jar
- /usr/local/opensearch/plugins/opensearch-notifications/httpcore-4.4.16.jar
- /usr/local/opensearch/plugins/opensearch-notifications/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-notifications/identity-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jackson-datatype-jsr310-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jakarta.json-2.0.0-module.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jakarta.json-api-2.1.3.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jakarta.json.bind-api-2.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jmespath-java-1.12.687.jar
- /usr/local/opensearch/plugins/opensearch-notifications/json-utils-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/jsr305-3.0.2.jar
- /usr/local/opensearch/plugins/opensearch-notifications/kms-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/kotlinx-coroutines-core-jvm-1.4.3.jar
- /usr/local/opensearch/plugins/opensearch-notifications/metrics-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-buffer-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-base-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-compression-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-http-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-http2-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-marshalling-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-codec-protobuf-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-handler-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-nio-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-resolver-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-transport-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-transport-classes-epoll-4.1.124.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/netty-transport-native-unix-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-java-3.3.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-notifications-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-remote-metadata-sdk-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-remote-metadata-sdk-aos-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-remote-metadata-sdk-ddb-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-remote-metadata-sdk-remote-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-notifications/parsson-1.1.7.jar
- /usr/local/opensearch/plugins/opensearch-notifications/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-notifications/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-notifications/profiles-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/protocol-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/regions-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/retries-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/retries-spi-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/sdk-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/sts-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/third-party-jackson-core-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/url-connection-client-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/utils-2.32.29.jar
- /usr/local/opensearch/plugins/opensearch-notifications/yasson-2.0.2.jar
- /usr/local/opensearch/plugins/opensearch-observability/
- /usr/local/opensearch/plugins/opensearch-observability/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-observability/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-observability/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-observability/json-20231013.jar
- /usr/local/opensearch/plugins/opensearch-observability/json-base-2.2.1.jar
- /usr/local/opensearch/plugins/opensearch-observability/json-flattener-0.15.1.jar
- /usr/local/opensearch/plugins/opensearch-observability/kotlin-stdlib-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-observability/kotlinx-coroutines-core-jvm-1.9.0.jar
- /usr/local/opensearch/plugins/opensearch-observability/opensearch-observability-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-observability/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-observability/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/bc-fips-2.1.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/bcpkix-fips-2.1.9.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/byte-buddy-1.9.7.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/byte-buddy-agent-1.9.7.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/checker-qual-3.29.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/error_prone_annotations-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/failureaccess-1.0.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/gson-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/guava-33.2.1-jre.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/jackson-module-paranamer-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/jooq-3.10.8.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/jsr305-3.0.2.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/mockito-core-2.23.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-buffer-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-codec-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-codec-http-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-codec-http2-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-codec-socks-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-handler-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-handler-proxy-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-resolver-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-transport-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/netty-transport-native-unix-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/objenesis-3.0.1.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/opensearch-performance-analyzer-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/performance-analyzer-commons-2.0.0.jar
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-performance-analyzer/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/gson-2.8.9.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/json-20231013.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/json-base-2.2.1.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/json-flattener-0.15.1.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/jsoup-1.15.3.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/kotlin-stdlib-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/kotlin-test-2.2.0.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/kotlinx-coroutines-core-jvm-1.3.9.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/opensearch-reports-scheduler-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-reports-scheduler/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-search-relevance/
- /usr/local/opensearch/plugins/opensearch-search-relevance/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-search-relevance/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-search-relevance/common-utils-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/commons-math3-3.6.1.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/commons-text-1.14.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/gson-2.13.1.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/guava-33.4.8-jre.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/javassist-3.30.2-GA.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/json-20250517.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/json-path-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/json-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/jtokkit-1.1.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/opensearch-ml-client-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/opensearch-search-relevance-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-search-relevance/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-search-relevance/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-search-relevance/reflections-0.9.12.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/
- /usr/local/opensearch/plugins/opensearch-security-analytics/accessors-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/commons-csv-1.10.0.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/guava-32.1.3-jre.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/json-path-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/json-smart-2.5.2.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/opensearch-security-analytics-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-security-analytics/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-security-analytics/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-security-analytics/security-analytics-commons-1.0.0.jar
- /usr/local/opensearch/plugins/opensearch-security/
- /usr/local/opensearch/plugins/opensearch-security/accessors-smart-2.6.0.jar
- /usr/local/opensearch/plugins/opensearch-security/aggs-matrix-stats-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/asm-9.9.jar
- /usr/local/opensearch/plugins/opensearch-security/bc-fips-2.1.2.jar
- /usr/local/opensearch/plugins/opensearch-security/bcpkix-fips-2.1.9.jar
- /usr/local/opensearch/plugins/opensearch-security/bcutil-fips-2.1.4.jar
- /usr/local/opensearch/plugins/opensearch-security/blake2b-2.0.0.jar
- /usr/local/opensearch/plugins/opensearch-security/checker-qual-3.52.0.jar
- /usr/local/opensearch/plugins/opensearch-security/commons-cli-1.10.0.jar
- /usr/local/opensearch/plugins/opensearch-security/commons-codec-1.20.0.jar
- /usr/local/opensearch/plugins/opensearch-security/commons-lang3-3.18.0.jar
- /usr/local/opensearch/plugins/opensearch-security/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-security/commons-text-1.14.0.jar
- /usr/local/opensearch/plugins/opensearch-security/compiler-0.9.14.jar
- /usr/local/opensearch/plugins/opensearch-security/cryptacular-1.2.7.jar
- /usr/local/opensearch/plugins/opensearch-security/eventbus-java-3.3.1.jar
- /usr/local/opensearch/plugins/opensearch-security/failureaccess-1.0.3.jar
- /usr/local/opensearch/plugins/opensearch-security/google-java-format-1.32.0.jar
- /usr/local/opensearch/plugins/opensearch-security/guava-33.5.0-jre.jar
- /usr/local/opensearch/plugins/opensearch-security/httpasyncclient-4.1.5.jar
- /usr/local/opensearch/plugins/opensearch-security/httpclient-4.5.14.jar
- /usr/local/opensearch/plugins/opensearch-security/httpclient5-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-security/httpclient5-cache-5.4.4.jar
- /usr/local/opensearch/plugins/opensearch-security/httpcore-4.4.16.jar
- /usr/local/opensearch/plugins/opensearch-security/httpcore5-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-security/httpcore5-h2-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-security/httpcore5-reactive-5.3.4.jar
- /usr/local/opensearch/plugins/opensearch-security/ipaddress-5.5.1.jar
- /usr/local/opensearch/plugins/opensearch-security/istack-commons-runtime-4.2.0.jar
- /usr/local/opensearch/plugins/opensearch-security/j2objc-annotations-3.1.jar
- /usr/local/opensearch/plugins/opensearch-security/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-security/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-security/jakarta.activation-1.2.2.jar
- /usr/local/opensearch/plugins/opensearch-security/jakarta.xml.bind-api-4.0.4.jar
- /usr/local/opensearch/plugins/opensearch-security/java-saml-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-security/java-saml-core-2.9.0.jar
- /usr/local/opensearch/plugins/opensearch-security/jaxb-runtime-2.3.9.jar
- /usr/local/opensearch/plugins/opensearch-security/jjwt-api-0.13.0.jar
- /usr/local/opensearch/plugins/opensearch-security/jjwt-impl-0.13.0.jar
- /usr/local/opensearch/plugins/opensearch-security/jjwt-jackson-0.13.0.jar
- /usr/local/opensearch/plugins/opensearch-security/kafka-clients-4.1.1.jar
- /usr/local/opensearch/plugins/opensearch-security/lang-mustache-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/ldaptive-1.2.3.jar
- /usr/local/opensearch/plugins/opensearch-security/log4j-slf4j-impl-2.21.0.jar
- /usr/local/opensearch/plugins/opensearch-security/lz4-java-1.10.1.jar
- /usr/local/opensearch/plugins/opensearch-security/mapper-extras-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/metrics-core-4.2.37.jar
- /usr/local/opensearch/plugins/opensearch-security/minimal-json-0.9.5.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-buffer-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-codec-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-codec-base-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-codec-compression-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-codec-http-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-codec-http2-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-handler-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-resolver-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-transport-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/netty-transport-native-unix-common-4.2.7.Final.jar
- /usr/local/opensearch/plugins/opensearch-security/nimbus-jose-jwt-10.6.jar
- /usr/local/opensearch/plugins/opensearch-security/opensaml-3.4.0.0-all.jar
- /usr/local/opensearch/plugins/opensearch-security/opensearch-rest-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/opensearch-rest-high-level-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/opensearch-security-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-security/opensearch-security-spi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-security/parent-join-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/passay-1.6.6.jar
- /usr/local/opensearch/plugins/opensearch-security/password4j-1.8.3.jar
- /usr/local/opensearch/plugins/opensearch-security/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-security/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-security/rank-eval-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/scala-java8-compat_3-1.0.2.jar
- /usr/local/opensearch/plugins/opensearch-security/slf4j-api-1.7.36.jar
- /usr/local/opensearch/plugins/opensearch-security/snappy-java-1.1.10.8.jar
- /usr/local/opensearch/plugins/opensearch-security/special-collections-complete-1.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/stax2-api-4.2.2.jar
- /usr/local/opensearch/plugins/opensearch-security/tools/
- /usr/local/opensearch/plugins/opensearch-security/tools/SECURITY_ADMIN_TESTS.md
- /usr/local/opensearch/plugins/opensearch-security/tools/audit_config_migrater.sh
- /usr/local/opensearch/plugins/opensearch-security/tools/hash.sh
- /usr/local/opensearch/plugins/opensearch-security/tools/install_demo_configuration.sh
- /usr/local/opensearch/plugins/opensearch-security/tools/securityadmin.sh
- /usr/local/opensearch/plugins/opensearch-security/transport-netty4-client-3.4.0.jar
- /usr/local/opensearch/plugins/opensearch-security/txw2-2.3.9.jar
- /usr/local/opensearch/plugins/opensearch-security/woodstox-core-6.7.0.jar
- /usr/local/opensearch/plugins/opensearch-security/xmlschema-core-2.3.2.jar
- /usr/local/opensearch/plugins/opensearch-security/xmlsec-2.3.5.jar
- /usr/local/opensearch/plugins/opensearch-security/zjsonpatch-0.4.16.jar
- /usr/local/opensearch/plugins/opensearch-security/zxcvbn-1.9.0.jar
- /usr/local/opensearch/plugins/opensearch-skills/
- /usr/local/opensearch/plugins/opensearch-skills/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-skills/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-skills/antlr4-runtime-4.9.3.jar
- /usr/local/opensearch/plugins/opensearch-skills/jackson-module-scala_3-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-skills/json4s-ast_2.13-3.7.0-M11.jar
- /usr/local/opensearch/plugins/opensearch-skills/json4s-core_2.13-3.7.0-M11.jar
- /usr/local/opensearch/plugins/opensearch-skills/json4s-jackson_2.13-3.7.0-M11.jar
- /usr/local/opensearch/plugins/opensearch-skills/jsoup-1.19.1.jar
- /usr/local/opensearch/plugins/opensearch-skills/opensearch-anomaly-detection-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-skills/opensearch-skills-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-skills/opensearch-sql-thin-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-skills/paranamer-2.8.jar
- /usr/local/opensearch/plugins/opensearch-skills/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-skills/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-skills/scala-library-2.13.9.jar
- /usr/local/opensearch/plugins/opensearch-skills/scala3-library_3-3.7.0-RC1-bin-20250119-bd699fc-NIGHTLY.jar
- /usr/local/opensearch/plugins/opensearch-skills/spark-common-utils_2.13-3.5.4.jar
- /usr/local/opensearch/plugins/opensearch-skills/spark-core_2.13-3.5.4.jar
- /usr/local/opensearch/plugins/opensearch-skills/spark-sql-api_2.13-3.5.4.jar
- /usr/local/opensearch/plugins/opensearch-sql/
- /usr/local/opensearch/plugins/opensearch-sql/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-sql/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-sql/opensearch-sql-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-sql/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-sql/plugin-security.policy
- /usr/local/opensearch/plugins/opensearch-system-templates/
- /usr/local/opensearch/plugins/opensearch-system-templates/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-system-templates/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-system-templates/opensearch-system-templates-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-system-templates/plugin-descriptor.properties
- /usr/local/opensearch/plugins/opensearch-ubi/
- /usr/local/opensearch/plugins/opensearch-ubi/LICENSE.txt
- /usr/local/opensearch/plugins/opensearch-ubi/NOTICE.txt
- /usr/local/opensearch/plugins/opensearch-ubi/commons-logging-1.3.5.jar
- /usr/local/opensearch/plugins/opensearch-ubi/httpclient-4.5.14.jar
- /usr/local/opensearch/plugins/opensearch-ubi/httpcore-4.4.16.jar
- /usr/local/opensearch/plugins/opensearch-ubi/jackson-annotations-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-ubi/jackson-databind-2.18.2.jar
- /usr/local/opensearch/plugins/opensearch-ubi/opensearch-ubi-3.4.0.0.jar
- /usr/local/opensearch/plugins/opensearch-ubi/plugin-descriptor.properties
- /usr/local/opensearch/plugins/query-insights/
- /usr/local/opensearch/plugins/query-insights/NOTICE.txt
- /usr/local/opensearch/plugins/query-insights/plugin-descriptor.properties
- /usr/local/opensearch/plugins/query-insights/query-insights-3.4.0.0.jar
- /usr/local/share/doc/opensearch/
- /usr/local/share/doc/opensearch/LICENSE.txt
- /usr/local/share/doc/opensearch/NOTICE.txt
- /usr/local/share/doc/opensearch/README.md
- /usr/local/share/doc/pkg-readmes/opensearch
- /usr/local/share/examples/login.conf.d/opensearch
- /usr/local/share/examples/opensearch/
- /usr/local/share/examples/opensearch/fips_java.security
- /usr/local/share/examples/opensearch/jvm.options
- /usr/local/share/examples/opensearch/jvm.options.d/
- /usr/local/share/examples/opensearch/log4j2.properties
- /usr/local/share/examples/opensearch/opensearch-notifications-core/
- /usr/local/share/examples/opensearch/opensearch-notifications-core/notifications-core.yml
- /usr/local/share/examples/opensearch/opensearch-notifications/
- /usr/local/share/examples/opensearch/opensearch-notifications/notifications.yml
- /usr/local/share/examples/opensearch/opensearch-observability/
- /usr/local/share/examples/opensearch/opensearch-observability/observability.yml
- /usr/local/share/examples/opensearch/opensearch-reports-scheduler/
- /usr/local/share/examples/opensearch/opensearch-reports-scheduler/reports-scheduler.yml
- /usr/local/share/examples/opensearch/opensearch-security/
- /usr/local/share/examples/opensearch/opensearch-security/action_groups.yml
- /usr/local/share/examples/opensearch/opensearch-security/allowlist.yml
- /usr/local/share/examples/opensearch/opensearch-security/audit.yml
- /usr/local/share/examples/opensearch/opensearch-security/config.yml
- /usr/local/share/examples/opensearch/opensearch-security/internal_users.yml
- /usr/local/share/examples/opensearch/opensearch-security/nodes_dn.yml
- /usr/local/share/examples/opensearch/opensearch-security/opensearch.yml.example
- /usr/local/share/examples/opensearch/opensearch-security/roles.yml
- /usr/local/share/examples/opensearch/opensearch-security/roles_mapping.yml
- /usr/local/share/examples/opensearch/opensearch-security/tenants.yml
- /usr/local/share/examples/opensearch/opensearch.yml
- /var/log/opensearch/
- /var/opensearch/
- @exec ln -s /usr/local/opensearch/opensearch-security-analytics /etc/opensearch/opensearch-security-analytics
- @extraunexec rm -rf /etc/opensearch/opensearch.keystore
- @extraunexec rm -rf /var/log/opensearch/*
- @extraunexec rm -rf /var/opensearch/*
- @newgroup _opensearch:881
- @newuser _opensearch:881:_opensearch::OpenSearch User:/nonexistent:/sbin/nologin
- @unexec rm -f /etc/opensearch/opensearch-security-analytics