Skip to content

[Rule Tuning] Not ECS field in rule Suspicious Web Browser Sensitive File Access#6200

Open
litemars wants to merge 2 commits into
elastic:mainfrom
litemars:credential_access_suspicious_web_browser_sensitive_file_access_tuning
Open

[Rule Tuning] Not ECS field in rule Suspicious Web Browser Sensitive File Access#6200
litemars wants to merge 2 commits into
elastic:mainfrom
litemars:credential_access_suspicious_web_browser_sensitive_file_access_tuning

Conversation

@litemars
Copy link
Copy Markdown
Contributor

@litemars litemars commented May 27, 2026

Pull Request

Issue link(s):

Summary - What I changed

The rule was utilising a not existing field in the query, making it silently fail.

  • Added a label for the type of pr: bug, enhancement, schema, maintenance, Rule: New, Rule: Deprecation, Rule: Tuning, Hunt: New, or Hunt: Tuning so guidelines can be generated

@litemars litemars changed the title [bug] Not ECS field in rule Suspicious Web Browser Sensitive File Access [Bug] Not ECS field in rule Suspicious Web Browser Sensitive File Access May 27, 2026
@eric-forte-elastic eric-forte-elastic added the enhancement New feature or request label May 27, 2026
@github-actions
Copy link
Copy Markdown
Contributor

Enhancement - Guidelines

These guidelines serve as a reminder set of considerations when addressing adding a feature to the code.

Documentation and Context

  • Describe the feature enhancement in detail (alternative solutions, description of the solution, etc.) if not already documented in an issue.
  • Include additional context or screenshots.
  • Ensure the enhancement includes necessary updates to the documentation and versioning.

Code Standards and Practices

  • Code follows established design patterns within the repo and avoids duplication.
  • Ensure that the code is modular and reusable where applicable.

Testing

  • New unit tests have been added to cover the enhancement.
  • Existing unit tests have been updated to reflect the changes.
  • Provide evidence of testing and validating the enhancement (e.g., test logs, screenshots).
  • Validate that any rules affected by the enhancement are correctly updated.
  • Ensure that performance is not negatively impacted by the changes.
  • Verify that any release artifacts are properly generated and tested.
  • Conducted system testing, including fleet, import, and create APIs (e.g., run make test-cli, make test-remote-cli, make test-hunting-cli)

Additional Checks

  • Verify that the enhancement works across all relevant environments (e.g., different OS versions).
  • Confirm that the proper version label is applied to the PR patch, minor, major.

Comment thread rules/macos/credential_access_suspicious_web_browser_sensitive_file_access.toml Outdated
@imays11 imays11 added the Rule: Tuning tweaking or tuning an existing rule label May 28, 2026
@imays11 imays11 changed the title [Bug] Not ECS field in rule Suspicious Web Browser Sensitive File Access [Rule Tuning] Not ECS field in rule Suspicious Web Browser Sensitive File Access May 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants