From 5b2965966ede3e2eac281ea95bdec18aed8c7078 Mon Sep 17 00:00:00 2001 From: Colleen McGinnis Date: Fri, 28 Feb 2025 13:46:02 -0600 Subject: [PATCH] clean up cross-repo links --- docs/reference/prebuilt-jobs.md | 32 +++++++++---------- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...t-intel-filebeat-module-indicator-match.md | 2 +- ...rebuilt-rule-0-14-3-hosts-file-modified.md | 2 +- ...el-filebeat-module-v7-x-indicator-match.md | 2 +- ...prebuilt-rule-1-0-2-hosts-file-modified.md | 2 +- ...el-filebeat-module-v8-x-indicator-match.md | 2 +- ...rule-1-0-2-threat-intel-indicator-match.md | 2 +- ...prebuilt-rule-8-1-1-hosts-file-modified.md | 2 +- ...le-8-17-2-login-via-unusual-system-user.md | 10 +++--- ...-17-3-attempt-to-disable-syslog-service.md | 8 ++--- ...16-or-base32-encoding-decoding-activity.md | 8 ++--- ...nnection-to-external-network-via-telnet.md | 8 ++--- ...nnection-to-internal-network-via-telnet.md | 8 ++--- ...3-creation-of-hidden-shared-object-file.md | 8 ++--- ...le-8-17-3-file-made-immutable-by-chattr.md | 8 ++--- ...sfer-or-listener-established-via-netcat.md | 8 ++--- ...uilt-rule-8-17-3-hping-process-activity.md | 8 ++--- ...-3-namespace-manipulation-using-unshare.md | 8 ++--- ...uilt-rule-8-17-3-nping-process-activity.md | 8 ++--- ...art-script-or-desktop-file-modification.md | 8 ++--- ...e-8-17-3-potential-disabling-of-selinux.md | 8 ++--- ...ntial-openssh-backdoor-logging-activity.md | 8 ++--- ...ential-protocol-tunneling-via-earthworm.md | 8 ++--- ...3-process-started-with-executable-stack.md | 10 +++--- ...lt-rule-8-17-3-system-log-file-deletion.md | 8 ++--- ...lt-rule-8-17-3-unusual-pkexec-execution.md | 8 ++--- ...-17-4-attempt-to-disable-syslog-service.md | 8 ++--- ...16-or-base32-encoding-decoding-activity.md | 8 ++--- ...nnection-to-external-network-via-telnet.md | 8 ++--- ...nnection-to-internal-network-via-telnet.md | 8 ++--- ...n-files-and-directories-via-commandline.md | 8 ++--- ...4-creation-of-hidden-shared-object-file.md | 8 ++--- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...le-8-17-4-file-made-immutable-by-chattr.md | 8 ++--- ...sion-modification-in-writable-directory.md | 8 ++--- ...sfer-or-listener-established-via-netcat.md | 8 ++--- ...auth-login-from-third-party-application.md | 2 +- ...tion-key-s-accessed-from-anonymous-user.md | 2 +- ...orkspace-suspended-user-account-renewed.md | 2 +- ...uilt-rule-8-17-4-hping-process-activity.md | 8 ++--- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- ...4-interactive-terminal-spawned-via-perl.md | 8 ++--- ...ebuilt-rule-8-17-4-linux-group-creation.md | 10 +++--- ...rule-8-17-4-linux-user-account-creation.md | 10 +++--- ...le-8-17-4-login-via-unusual-system-user.md | 10 +++--- ...ns-request-predicted-to-be-a-dga-domain.md | 4 +-- ...quest-with-a-high-dga-probability-score.md | 4 +-- ...with-a-high-malicious-probability-score.md | 4 +-- ...-with-a-low-malicious-probability-score.md | 4 +-- ...ivity-using-a-known-sunburst-dns-domain.md | 4 +-- ...of-dynamic-linker-preload-shared-object.md | 8 ++--- ...8-17-4-modification-of-openssh-binaries.md | 8 ++--- ...-4-namespace-manipulation-using-unshare.md | 8 ++--- ...s-initiated-through-xdg-autostart-entry.md | 8 ++--- ...uilt-rule-8-17-4-nping-process-activity.md | 8 ++--- ...art-script-or-desktop-file-modification.md | 8 ++--- ...uilt-rule-8-17-4-potential-dga-activity.md | 4 +-- ...e-8-17-4-potential-disabling-of-selinux.md | 8 ++--- ...external-linux-ssh-brute-force-detected.md | 10 +++--- ...internal-linux-ssh-brute-force-detected.md | 10 +++--- ...7-4-potential-meterpreter-reverse-shell.md | 8 ++--- ...ntial-openssh-backdoor-logging-activity.md | 8 ++--- ...ential-protocol-tunneling-via-earthworm.md | 8 ++--- ...-8-17-4-potential-reverse-shell-via-udp.md | 8 ++--- ...l-linux-ftp-brute-force-attack-detected.md | 8 ++--- ...l-linux-rdp-brute-force-attack-detected.md | 8 ++--- ...ntial-successful-ssh-brute-force-attack.md | 18 +++++------ ...-process-backgrounded-by-unusual-parent.md | 8 ++--- ...4-process-started-with-executable-stack.md | 10 +++--- ...-rapid7-threat-command-cves-correlation.md | 2 +- ...rule-8-17-4-sensitive-files-compression.md | 8 ++--- ...ternet-by-previously-unknown-executable.md | 24 +++++++------- ...-17-4-suspicious-rc-local-error-message.md | 10 +++--- ...us-usage-of-bpf-probe-write-user-helper.md | 10 +++--- ...ndows-process-cluster-spawned-by-a-host.md | 4 +-- ...ess-cluster-spawned-by-a-parent-process.md | 4 +-- ...ndows-process-cluster-spawned-by-a-user.md | 4 +-- ...lt-rule-8-17-4-system-log-file-deletion.md | 8 ++--- ...-rule-8-17-4-tainted-kernel-module-load.md | 10 +++--- ...-tainted-out-of-tree-kernel-module-load.md | 10 +++--- ...-17-4-threat-intel-hash-indicator-match.md | 2 +- ...threat-intel-ip-address-indicator-match.md | 2 +- ...8-17-4-threat-intel-url-indicator-match.md | 2 +- ...-intel-windows-registry-indicator-match.md | 2 +- ...lt-rule-8-17-4-unusual-pkexec-execution.md | 8 ++--- ...-17-4-unusual-process-spawned-by-a-host.md | 4 +-- ...ual-process-spawned-by-a-parent-process.md | 4 +-- ...-17-4-unusual-process-spawned-by-a-user.md | 4 +-- ...e-8-17-4-virtual-machine-fingerprinting.md | 8 ++--- ...prebuilt-rule-8-2-1-hosts-file-modified.md | 2 +- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- ...prebuilt-rule-8-3-2-hosts-file-modified.md | 2 +- ...el-filebeat-module-v8-x-indicator-match.md | 2 +- ...rule-8-3-2-threat-intel-indicator-match.md | 2 +- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...prebuilt-rule-8-3-3-hosts-file-modified.md | 2 +- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- ...el-filebeat-module-v8-x-indicator-match.md | 2 +- ...rule-8-3-3-threat-intel-indicator-match.md | 2 +- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...prebuilt-rule-8-4-1-hosts-file-modified.md | 2 +- ...el-filebeat-module-v8-x-indicator-match.md | 2 +- ...rule-8-4-1-threat-intel-indicator-match.md | 2 +- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...prebuilt-rule-8-4-2-hosts-file-modified.md | 2 +- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- ...el-filebeat-module-v8-x-indicator-match.md | 2 +- ...rule-8-4-2-threat-intel-indicator-match.md | 2 +- ...cation-added-to-google-workspace-domain.md | 2 +- ...oved-from-blocklist-in-google-workspace.md | 2 +- .../attempt-to-disable-syslog-service.md | 8 ++--- ...16-or-base32-encoding-decoding-activity.md | 8 ++--- ...nnection-to-external-network-via-telnet.md | 8 ++--- ...nnection-to-internal-network-via-telnet.md | 8 ++--- ...n-files-and-directories-via-commandline.md | 8 ++--- .../creation-of-hidden-shared-object-file.md | 8 ++--- ...t-cobalt-strike-team-server-certificate.md | 2 +- ...ded-to-google-workspace-trusted-domains.md | 2 +- ...al-user-added-to-google-workspace-group.md | 2 +- .../file-made-immutable-by-chattr.md | 8 ++--- ...sion-modification-in-writable-directory.md | 8 ++--- ...sfer-or-listener-established-via-netcat.md | 8 ++--- ...auth-login-from-third-party-application.md | 2 +- ...ership-transferred-via-google-workspace.md | 2 +- .../google-workspace-2sv-policy-disabled.md | 2 +- ...workspace-admin-role-assigned-to-a-user.md | 2 +- .../google-workspace-admin-role-deletion.md | 2 +- ...cess-granted-via-domain-wide-delegation.md | 2 +- ...le-workspace-bitlocker-setting-disabled.md | 2 +- ...gle-workspace-custom-admin-role-created.md | 2 +- ...-custom-gmail-route-created-or-modified.md | 2 +- ...tion-key-s-accessed-from-anonymous-user.md | 2 +- ...ogle-workspace-mfa-enforcement-disabled.md | 2 +- ...pied-to-external-drive-with-app-consent.md | 2 +- ...ogle-workspace-password-policy-modified.md | 2 +- ...r-marketplace-modified-to-allow-any-app.md | 2 +- .../google-workspace-role-modified.md | 2 +- ...orkspace-suspended-user-account-renewed.md | 2 +- ...kspace-user-organizational-unit-changed.md | 2 +- .../prebuilt-rules/hosts-file-modified.md | 2 +- .../prebuilt-rules/hping-process-activity.md | 8 ++--- ...ction-to-an-unsecure-elasticsearch-node.md | 2 +- .../interactive-terminal-spawned-via-perl.md | 8 ++--- .../prebuilt-rules/linux-group-creation.md | 10 +++--- .../linux-user-account-creation.md | 10 +++--- .../login-via-unusual-system-user.md | 10 +++--- ...ns-request-predicted-to-be-a-dga-domain.md | 4 +-- ...quest-with-a-high-dga-probability-score.md | 4 +-- ...with-a-high-malicious-probability-score.md | 4 +-- ...-with-a-low-malicious-probability-score.md | 4 +-- ...ivity-using-a-known-sunburst-dns-domain.md | 4 +-- ...abled-for-google-workspace-organization.md | 2 +- ...of-dynamic-linker-preload-shared-object.md | 8 ++--- .../modification-of-openssh-binaries.md | 8 ++--- .../namespace-manipulation-using-unshare.md | 8 ++--- ...s-initiated-through-xdg-autostart-entry.md | 8 ++--- .../prebuilt-rules/nping-process-activity.md | 8 ++--- ...art-script-or-desktop-file-modification.md | 8 ++--- .../prebuilt-rules/potential-dga-activity.md | 4 +-- .../potential-disabling-of-selinux.md | 8 ++--- ...external-linux-ssh-brute-force-detected.md | 10 +++--- ...internal-linux-ssh-brute-force-detected.md | 10 +++--- .../potential-meterpreter-reverse-shell.md | 8 ++--- ...ntial-openssh-backdoor-logging-activity.md | 8 ++--- ...ential-protocol-tunneling-via-earthworm.md | 8 ++--- .../potential-reverse-shell-via-udp.md | 8 ++--- ...l-linux-ftp-brute-force-attack-detected.md | 8 ++--- ...l-linux-rdp-brute-force-attack-detected.md | 8 ++--- ...ntial-successful-ssh-brute-force-attack.md | 18 +++++------ .../process-backgrounded-by-unusual-parent.md | 8 ++--- .../process-started-with-executable-stack.md | 10 +++--- .../rapid7-threat-command-cves-correlation.md | 2 +- .../prebuilt-rules/segfault-detected.md | 10 +++--- .../sensitive-files-compression.md | 8 ++--- ...ternet-by-previously-unknown-executable.md | 24 +++++++------- .../suspicious-rc-local-error-message.md | 10 +++--- ...us-usage-of-bpf-probe-write-user-helper.md | 10 +++--- ...ndows-process-cluster-spawned-by-a-host.md | 4 +-- ...ess-cluster-spawned-by-a-parent-process.md | 4 +-- ...ndows-process-cluster-spawned-by-a-user.md | 4 +-- .../system-log-file-deletion.md | 8 ++--- .../tainted-kernel-module-load.md | 10 +++--- .../tainted-out-of-tree-kernel-module-load.md | 10 +++--- .../threat-intel-hash-indicator-match.md | 2 +- ...threat-intel-ip-address-indicator-match.md | 2 +- .../threat-intel-url-indicator-match.md | 2 +- ...-intel-windows-registry-indicator-match.md | 2 +- .../unusual-pkexec-execution.md | 8 ++--- .../unusual-process-spawned-by-a-host.md | 4 +-- ...ual-process-spawned-by-a-parent-process.md | 4 +-- .../unusual-process-spawned-by-a-user.md | 4 +-- .../virtual-machine-fingerprinting.md | 8 ++--- 195 files changed, 586 insertions(+), 586 deletions(-) diff --git a/docs/reference/prebuilt-jobs.md b/docs/reference/prebuilt-jobs.md index edff301c37..315ebf45e7 100644 --- a/docs/reference/prebuilt-jobs.md +++ b/docs/reference/prebuilt-jobs.md @@ -12,7 +12,7 @@ These {{anomaly-jobs}} automatically detect file system and network anomalies on Detect anomalous activity in your ECS-compatible authentication logs. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_auth/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_auth/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. By default, when you create these job in the {{security-app}}, it uses a {{data-source}} that applies to multiple indices. To get the same results if you use the {{ml-app}} app, create a similar [{{data-source}}](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_auth/manifest.json#L7) then select it in the job wizard. @@ -31,7 +31,7 @@ By default, when you create these job in the {{security-app}}, it uses a {{data- Detect suspicious activity recorded in your CloudTrail logs. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_cloudtrail/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_cloudtrail/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. | Name | Description | Job | Datafeed | | --- | --- | --- | --- | @@ -46,7 +46,7 @@ In the {{ml-app}} app, these configurations are available only when data exists Anomaly detection jobs for host-based threat hunting and detection. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_host/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/platform/plugins/shared/ml/server/models/data_recognizer/modules/security_host/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. To access the host traffic anomalies dashboard in Kibana, go to: `Security -> Dashboards -> Host Traffic Anomalies`. @@ -60,7 +60,7 @@ To access the host traffic anomalies dashboard in Kibana, go to: `Security -> Da Anomaly detection jobs for Linux host-based threat hunting and detection. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_linux/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_linux/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. | Name | Description | Job | Datafeed | | --- | --- | --- | --- | @@ -84,7 +84,7 @@ In the {{ml-app}} app, these configurations are available only when data exists Detect anomalous network activity in your ECS-compatible network logs. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_network/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_network/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. By default, when you create these jobs in the {{security-app}}, it uses a {{data-source}} that applies to multiple indices. To get the same results if you use the {{ml-app}} app, create a similar [{{data-source}}](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_network/manifest.json#L7) then select it in the job wizard. @@ -100,7 +100,7 @@ By default, when you create these jobs in the {{security-app}}, it uses a {{data Detect suspicious network activity in {{packetbeat}} data. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_packetbeat/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_packetbeat/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. | Name | Description | Job | Datafeed | | --- | --- | --- | --- | @@ -115,7 +115,7 @@ In the {{ml-app}} app, these configurations are available only when data exists Anomaly detection jobs for Windows host-based threat hunting and detection. -In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://docs/reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. +In the {{ml-app}} app, these configurations are available only when data exists that matches the query specified in the [manifest file](https://github.com/elastic/kibana/blob/master/x-pack/plugins/ml/server/models/data_recognizer/modules/security_windows/manifest.json). In the {{security-app}}, it looks in the {{data-source}} specified in the [`securitySolution:defaultIndex` advanced setting](kibana://reference/advanced-settings.md#securitysolution-defaultindex) for data that matches the query. If there are additional requirements such as installing the Windows System Monitor (Sysmon) or auditing process creation in the Windows security event log, they are listed for each job. @@ -137,20 +137,20 @@ If there are additional requirements such as installing the Windows System Monit ## Security: Elastic Integrations [security-integrations-jobs] -[Elastic Integrations](integration-docs://docs/reference/index.md) are a streamlined way to add Elastic assets to your environment, such as data ingestion, {{transforms}}, and in this case, {{ml}} capabilities for Security. +[Elastic Integrations](integration-docs://reference/index.md) are a streamlined way to add Elastic assets to your environment, such as data ingestion, {{transforms}}, and in this case, {{ml}} capabilities for Security. The following Integrations use {{ml}} to analyze patterns of user and entity behavior, and help detect and alert when there is related suspicious activity in your environment. -* [Data Exfiltration Detection](integration-docs://docs/reference/ded.md) -* [Domain Generation Algorithm Detection](integration-docs://docs/reference/dga.md) -* [Lateral Movement Detection](integration-docs://docs/reference/lmd.md) -* [Living off the Land Attack Detection](integration-docs://docs/reference/problemchild.md) +* [Data Exfiltration Detection](integration-docs://reference/ded.md) +* [Domain Generation Algorithm Detection](integration-docs://reference/dga.md) +* [Lateral Movement Detection](integration-docs://reference/lmd.md) +* [Living off the Land Attack Detection](integration-docs://reference/problemchild.md) **Domain Generation Algorithm (DGA) Detection** {{ml-cap}} solution package to detect domain generation algorithm (DGA) activity in your network data. Refer to the [subscription page](https://www.elastic.co/subscriptions) to learn more about the required subscription. -To download, refer to the [documentation](integration-docs://docs/reference/dga.md). +To download, refer to the [documentation](integration-docs://reference/dga.md). | Name | Description | | --- | --- | @@ -162,7 +162,7 @@ The job configurations and datafeeds can be found [here](https://github.com/elas {{ml-cap}} solution package to detect Living off the Land (LotL) attacks in your environment. Refer to the [subscription page](https://www.elastic.co/subscriptions) to learn more about the required subscription. (Also known as ProblemChild). -To download, refer to the [documentation](integration-docs://docs/reference/problemchild.md). +To download, refer to the [documentation](integration-docs://reference/problemchild.md). | Name | Description | | --- | --- | @@ -179,7 +179,7 @@ The job configurations and datafeeds can be found [here](https://github.com/elas {{ml-cap}} package to detect data exfiltration in your network and file data. Refer to the [subscription page](https://www.elastic.co/subscriptions) to learn more about the required subscription. -To download, refer to the [documentation](integration-docs://docs/reference/ded.md). +To download, refer to the [documentation](integration-docs://reference/ded.md). | Name | Description | | --- | --- | @@ -197,7 +197,7 @@ The job configurations and datafeeds can be found [here](https://github.com/elas {{ml-cap}} package to detect lateral movement based on file transfer activity and Windows RDP events. Refer to the [subscription page](https://www.elastic.co/subscriptions) to learn more about the required subscription. -To download, refer to the [documentation](integration-docs://docs/reference/lmd.md). +To download, refer to the [documentation](integration-docs://reference/lmd.md). | Name | Description | | --- | --- | diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-default-cobalt-strike-team-server-certificate.md index 3a76fe2cff..a2bfb76d6f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-inbound-connection-to-an-unsecure-elasticsearch-node.md index dba56b0f6c..22ea992a17 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-13-3-inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -29,7 +29,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-1-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-1-default-cobalt-strike-team-server-certificate.md index 6044e99043..3e43db32b0 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-1-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-1-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-2-threat-intel-filebeat-module-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-2-threat-intel-filebeat-module-indicator-match.md index 0dcfeb0a83..4aedf494aa 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-2-threat-intel-filebeat-module-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-2-threat-intel-filebeat-module-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module has **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-hosts-file-modified.md index 629b20063d..12910eb1b5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-threat-intel-filebeat-module-v7-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-threat-intel-filebeat-module-v7-x-indicator-match.md index 3666d5b902..33140c224b 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-threat-intel-filebeat-module-v7-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-0-14-3-threat-intel-filebeat-module-v7-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v7 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-hosts-file-modified.md index 1882e1a389..639f19c67e 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP-address-to-hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-filebeat-module-v8-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-filebeat-module-v8-x-indicator-match.md index 93fb874877..ca97a54088 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-filebeat-module-v8-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-filebeat-module-v8-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v8 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-indicator-match.md index cea840c338..5070949a92 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-1-0-2-threat-intel-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel integrations have a **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-1-1-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-1-1-hosts-file-modified.md index 229c60e2d1..8bd00cf40e 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-1-1-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-1-1-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-2-login-via-unusual-system-user.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-2-login-via-unusual-system-user.md index 70e2df21db..c8c5704f17 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-2-login-via-unusual-system-user.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-2-login-via-unusual-system-user.md @@ -59,17 +59,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_4807] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-attempt-to-disable-syslog-service.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-attempt-to-disable-syslog-service.md index 689bb37586..8f76541532 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-attempt-to-disable-syslog-service.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-attempt-to-disable-syslog-service.md @@ -85,10 +85,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4866] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-base16-or-base32-encoding-decoding-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-base16-or-base32-encoding-decoding-activity.md index c744009655..d7a385b742 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-base16-or-base32-encoding-decoding-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-base16-or-base32-encoding-decoding-activity.md @@ -85,10 +85,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4867] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-external-network-via-telnet.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-external-network-via-telnet.md index f221b71a69..918ffae4bd 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-external-network-via-telnet.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-external-network-via-telnet.md @@ -80,10 +80,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4923] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-internal-network-via-telnet.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-internal-network-via-telnet.md index 13192b3778..d5ab114b62 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-internal-network-via-telnet.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-connection-to-internal-network-via-telnet.md @@ -80,10 +80,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4924] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-creation-of-hidden-shared-object-file.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-creation-of-hidden-shared-object-file.md index c9335c1835..c94b603aa5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-creation-of-hidden-shared-object-file.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-creation-of-hidden-shared-object-file.md @@ -81,10 +81,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-made-immutable-by-chattr.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-made-immutable-by-chattr.md index 47b37eb26a..a93cf0ba74 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-made-immutable-by-chattr.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-made-immutable-by-chattr.md @@ -81,10 +81,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-transfer-or-listener-established-via-netcat.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-transfer-or-listener-established-via-netcat.md index 2c004440e3..c92d178771 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-transfer-or-listener-established-via-netcat.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-file-transfer-or-listener-established-via-netcat.md @@ -128,10 +128,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4907] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-hping-process-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-hping-process-activity.md index 0678d28653..79092da169 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-hping-process-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-hping-process-activity.md @@ -87,10 +87,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4893] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-namespace-manipulation-using-unshare.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-namespace-manipulation-using-unshare.md index 4088ec7e08..071cbd313b 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-namespace-manipulation-using-unshare.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-namespace-manipulation-using-unshare.md @@ -84,10 +84,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4954] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-nping-process-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-nping-process-activity.md index 64dd65ce81..5a0e8e4bc9 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-nping-process-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-nping-process-activity.md @@ -87,10 +87,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4894] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-persistence-via-kde-autostart-script-or-desktop-file-modification.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-persistence-via-kde-autostart-script-or-desktop-file-modification.md index a05f4c58be..f89574cb37 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-persistence-via-kde-autostart-script-or-desktop-file-modification.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-persistence-via-kde-autostart-script-or-desktop-file-modification.md @@ -148,10 +148,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-disabling-of-selinux.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-disabling-of-selinux.md index c7574cadf6..e79af61033 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-disabling-of-selinux.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-disabling-of-selinux.md @@ -85,10 +85,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4873] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-openssh-backdoor-logging-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-openssh-backdoor-logging-activity.md index c30d3570e5..3e683f4306 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-openssh-backdoor-logging-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-openssh-backdoor-logging-activity.md @@ -85,10 +85,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-protocol-tunneling-via-earthworm.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-protocol-tunneling-via-earthworm.md index fbbd8f8319..050da1feba 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-protocol-tunneling-via-earthworm.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-potential-protocol-tunneling-via-earthworm.md @@ -147,10 +147,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-process-started-with-executable-stack.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-process-started-with-executable-stack.md index 5ba421a93e..08a046375f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-process-started-with-executable-stack.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-process-started-with-executable-stack.md @@ -54,17 +54,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_4829] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-system-log-file-deletion.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-system-log-file-deletion.md index 3662447fb5..6edeed4556 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-system-log-file-deletion.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-system-log-file-deletion.md @@ -84,10 +84,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-unusual-pkexec-execution.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-unusual-pkexec-execution.md index cc821fa617..4a7ea148f2 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-unusual-pkexec-execution.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-3-unusual-pkexec-execution.md @@ -83,10 +83,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4832] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-attempt-to-disable-syslog-service.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-attempt-to-disable-syslog-service.md index a84ea0cc90..4e0c8bacb6 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-attempt-to-disable-syslog-service.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-attempt-to-disable-syslog-service.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5322] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-base16-or-base32-encoding-decoding-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-base16-or-base32-encoding-decoding-activity.md index e855780224..5bae20f887 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-base16-or-base32-encoding-decoding-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-base16-or-base32-encoding-decoding-activity.md @@ -123,10 +123,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5323] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-external-network-via-telnet.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-external-network-via-telnet.md index 35531bc3cc..8e4d2078ea 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-external-network-via-telnet.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-external-network-via-telnet.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5425] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-internal-network-via-telnet.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-internal-network-via-telnet.md index cf9d384894..eabe827d1f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-internal-network-via-telnet.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-connection-to-internal-network-via-telnet.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5426] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-files-and-directories-via-commandline.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-files-and-directories-via-commandline.md index 1f6d73248a..67aff2cafa 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-files-and-directories-via-commandline.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-files-and-directories-via-commandline.md @@ -114,10 +114,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-shared-object-file.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-shared-object-file.md index 884a8839b9..1c35782394 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-shared-object-file.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-creation-of-hidden-shared-object-file.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-default-cobalt-strike-team-server-certificate.md index 2be564ed39..ef96d012ef 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) * [https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack](https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-made-immutable-by-chattr.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-made-immutable-by-chattr.md index 0ec41fef96..5675a113f3 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-made-immutable-by-chattr.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-made-immutable-by-chattr.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-permission-modification-in-writable-directory.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-permission-modification-in-writable-directory.md index 4ab54924ca..3f57c63e17 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-permission-modification-in-writable-directory.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-permission-modification-in-writable-directory.md @@ -113,10 +113,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5335] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-transfer-or-listener-established-via-netcat.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-transfer-or-listener-established-via-netcat.md index 159a3e6697..7a3ae4e2c1 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-transfer-or-listener-established-via-netcat.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-file-transfer-or-listener-established-via-netcat.md @@ -128,10 +128,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5387] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-first-time-seen-google-workspace-oauth-login-from-third-party-application.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-first-time-seen-google-workspace-oauth-login-from-third-party-application.md index 6adc1faba3..f7aa46bfde 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-first-time-seen-google-workspace-oauth-login-from-third-party-application.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-first-time-seen-google-workspace-oauth-login-from-third-party-application.md @@ -92,7 +92,7 @@ OAuth is a protocol that allows third-party applications to access user data wit * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_1052] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md index a633eb8aa6..70d8729c4c 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md @@ -90,7 +90,7 @@ Google Workspace Drive allows users to store and share files, including sensitiv * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_1051] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-suspended-user-account-renewed.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-suspended-user-account-renewed.md index bbd951b8a1..e915290b90 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-suspended-user-account-renewed.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-google-workspace-suspended-user-account-renewed.md @@ -87,7 +87,7 @@ Google Workspace manages user identities and access, crucial for organizational * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_1054] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-hping-process-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-hping-process-activity.md index c7d0d6e905..9d1610219c 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-hping-process-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-hping-process-activity.md @@ -125,10 +125,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5361] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-inbound-connection-to-an-unsecure-elasticsearch-node.md index 6e2d8ecab6..2999a1b915 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -27,7 +27,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-interactive-terminal-spawned-via-perl.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-interactive-terminal-spawned-via-perl.md index 89d7f14839..92957a9804 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-interactive-terminal-spawned-via-perl.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-interactive-terminal-spawned-via-perl.md @@ -116,10 +116,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5392] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-group-creation.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-group-creation.md index 670a9256f2..da2896ea31 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-group-creation.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-group-creation.md @@ -104,17 +104,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5458] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-user-account-creation.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-user-account-creation.md index fd5710b2d7..cd4137f993 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-user-account-creation.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-linux-user-account-creation.md @@ -103,17 +103,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5460] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-login-via-unusual-system-user.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-login-via-unusual-system-user.md index bcce0245ac..c40cc3ed50 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-login-via-unusual-system-user.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-login-via-unusual-system-user.md @@ -97,17 +97,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5486] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md index a04539be37..5075fb519a 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md @@ -100,10 +100,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md index e7e05c31f8..3ea4ac490a 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md @@ -99,10 +99,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md index 63193bcc15..5f95383a28 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md @@ -101,9 +101,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md index a3691152c9..a051603ef1 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md @@ -101,9 +101,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md index 658ef652ae..020e33dbb5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md @@ -100,10 +100,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-dynamic-linker-preload-shared-object.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-dynamic-linker-preload-shared-object.md index ed89396deb..348790afdf 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-dynamic-linker-preload-shared-object.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-dynamic-linker-preload-shared-object.md @@ -119,10 +119,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5513] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-openssh-binaries.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-openssh-binaries.md index aae175c6a0..4269efd714 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-openssh-binaries.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-modification-of-openssh-binaries.md @@ -143,10 +143,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5433] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-namespace-manipulation-using-unshare.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-namespace-manipulation-using-unshare.md index 2d8ee9b2bd..f1b402b2e3 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-namespace-manipulation-using-unshare.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-namespace-manipulation-using-unshare.md @@ -120,10 +120,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5535] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-network-connections-initiated-through-xdg-autostart-entry.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-network-connections-initiated-through-xdg-autostart-entry.md index 773d6b1d50..3f23862e7f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-network-connections-initiated-through-xdg-autostart-entry.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-network-connections-initiated-through-xdg-autostart-entry.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-nping-process-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-nping-process-activity.md index 5d229dfba3..2d997f904c 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-nping-process-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-nping-process-activity.md @@ -125,10 +125,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5362] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-persistence-via-kde-autostart-script-or-desktop-file-modification.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-persistence-via-kde-autostart-script-or-desktop-file-modification.md index d9c1ee0840..56a0634dc6 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-persistence-via-kde-autostart-script-or-desktop-file-modification.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-persistence-via-kde-autostart-script-or-desktop-file-modification.md @@ -149,10 +149,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-dga-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-dga-activity.md index 1f3cf2784b..0dfcf3a218 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-dga-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-dga-activity.md @@ -93,10 +93,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-disabling-of-selinux.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-disabling-of-selinux.md index 8886c06280..07af1cba86 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-disabling-of-selinux.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-disabling-of-selinux.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5330] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-external-linux-ssh-brute-force-detected.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-external-linux-ssh-brute-force-detected.md index a3b4db478b..a85e02cfe7 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-external-linux-ssh-brute-force-detected.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-external-linux-ssh-brute-force-detected.md @@ -95,17 +95,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5311] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-internal-linux-ssh-brute-force-detected.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-internal-linux-ssh-brute-force-detected.md index ff956ffb2c..86262530e1 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-internal-linux-ssh-brute-force-detected.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-internal-linux-ssh-brute-force-detected.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5312] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-meterpreter-reverse-shell.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-meterpreter-reverse-shell.md index ca61e6e368..a8e7a1f350 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-meterpreter-reverse-shell.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-meterpreter-reverse-shell.md @@ -95,10 +95,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-openssh-backdoor-logging-activity.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-openssh-backdoor-logging-activity.md index b493d304da..e804ba7bdc 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-openssh-backdoor-logging-activity.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-openssh-backdoor-logging-activity.md @@ -123,10 +123,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-protocol-tunneling-via-earthworm.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-protocol-tunneling-via-earthworm.md index 0c058e1cfc..6da44b4e6a 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-protocol-tunneling-via-earthworm.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-protocol-tunneling-via-earthworm.md @@ -148,10 +148,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-reverse-shell-via-udp.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-reverse-shell-via-udp.md index 7ef4384b22..4984e7da2c 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-reverse-shell-via-udp.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-reverse-shell-via-udp.md @@ -97,10 +97,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-ftp-brute-force-attack-detected.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-ftp-brute-force-attack-detected.md index e21a988b6c..4500cc7cc1 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-ftp-brute-force-attack-detected.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-ftp-brute-force-attack-detected.md @@ -91,10 +91,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-rdp-brute-force-attack-detected.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-rdp-brute-force-attack-detected.md index b2d331f166..7db88010f5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-rdp-brute-force-attack-detected.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-linux-rdp-brute-force-attack-detected.md @@ -92,10 +92,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-ssh-brute-force-attack.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-ssh-brute-force-attack.md index b633b83298..9e7899e786 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-ssh-brute-force-attack.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-potential-successful-ssh-brute-force-attack.md @@ -88,10 +88,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Filebeat Setup** @@ -100,17 +100,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5315] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-backgrounded-by-unusual-parent.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-backgrounded-by-unusual-parent.md index 94bade6583..ecc43773da 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-backgrounded-by-unusual-parent.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-backgrounded-by-unusual-parent.md @@ -120,10 +120,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_4959] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-started-with-executable-stack.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-started-with-executable-stack.md index b3efde2fc8..1e0a6d16c0 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-started-with-executable-stack.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-process-started-with-executable-stack.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5385] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-rapid7-threat-command-cves-correlation.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-rapid7-threat-command-cves-correlation.md index 7a277be41a..44d7f2c013 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-rapid7-threat-command-cves-correlation.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-rapid7-threat-command-cves-correlation.md @@ -30,7 +30,7 @@ This rule is triggered when CVEs collected from the Rapid7 Threat Command Integr **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [https://docs.elastic.co/integrations/ti_rapid7_threat_command](https://docs.elastic.co/integrations/ti_rapid7_threat_command) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-sensitive-files-compression.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-sensitive-files-compression.md index c8f24c1bc9..4dab2cee3d 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-sensitive-files-compression.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-sensitive-files-compression.md @@ -119,10 +119,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5306] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md index 701320d812..2b5525698a 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md @@ -140,10 +140,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Filebeat Setup** @@ -152,11 +152,11 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Packetbeat Setup** @@ -165,10 +165,10 @@ Packetbeat is a real-time network packet analyzer that you can use for applicati **The following steps should be executed in order to add the Packetbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/packetbeat/setup-repositories.md). -* To run Packetbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/packetbeat/running-on-docker.md). -* For quick start information for Packetbeat refer to the [helper guide](beats://docs/reference/packetbeat/packetbeat-installation-configuration.md). -* For complete “Setup and Run Packetbeat” information refer to the [helper guide](beats://docs/reference/packetbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/packetbeat/setup-repositories.md). +* To run Packetbeat on Docker follow the setup instructions in the [helper guide](beats://reference/packetbeat/running-on-docker.md). +* For quick start information for Packetbeat refer to the [helper guide](beats://reference/packetbeat/packetbeat-installation-configuration.md). +* For complete “Setup and Run Packetbeat” information refer to the [helper guide](beats://reference/packetbeat/setting-up-running.md). ## Rule query [_rule_query_5304] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-rc-local-error-message.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-rc-local-error-message.md index 811f7534ee..b1e59458b3 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-rc-local-error-message.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-rc-local-error-message.md @@ -94,17 +94,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5474] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-usage-of-bpf-probe-write-user-helper.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-usage-of-bpf-probe-write-user-helper.md index ae423bc45b..f75b20b031 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-usage-of-bpf-probe-write-user-helper.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-usage-of-bpf-probe-write-user-helper.md @@ -92,17 +92,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_4960] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-host.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-host.md index def0e9a83e..bb0e810c7f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-host.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-host.md @@ -94,9 +94,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-parent-process.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-parent-process.md index 2773d07e60..3f64ce6806 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-parent-process.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-parent-process.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-user.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-user.md index 9a865405a9..8e80341c79 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-user.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-suspicious-windows-process-cluster-spawned-by-a-user.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-system-log-file-deletion.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-system-log-file-deletion.md index 2160f29169..5f08ad714f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-system-log-file-deletion.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-system-log-file-deletion.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-kernel-module-load.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-kernel-module-load.md index 52ef92a8b9..b9d8f857a7 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-kernel-module-load.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-kernel-module-load.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5495] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-out-of-tree-kernel-module-load.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-out-of-tree-kernel-module-load.md index e973cc17ce..4c9ed1371c 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-out-of-tree-kernel-module-load.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-tainted-out-of-tree-kernel-module-load.md @@ -92,17 +92,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_5496] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-hash-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-hash-indicator-match.md index 0cc901171d..dc07c8dca2 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-hash-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-hash-indicator-match.md @@ -29,7 +29,7 @@ This rule is triggered when a hash indicator from the Threat Intel Filebeat modu **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-ip-address-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-ip-address-indicator-match.md index 016e4b7777..4aefeb0144 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-ip-address-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-ip-address-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when an IP address indicator from the Threat Intel Filebe **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-url-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-url-indicator-match.md index 0ec0caf650..0a72c1d824 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-url-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-url-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when a URL indicator from the Threat Intel Filebeat modul **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-windows-registry-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-windows-registry-indicator-match.md index 5e7040c7f0..b1d3136607 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-windows-registry-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-threat-intel-windows-registry-indicator-match.md @@ -29,7 +29,7 @@ This rule is triggered when a Windows registry indicator from the Threat Intel F **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-pkexec-execution.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-pkexec-execution.md index c676f563ab..0656ef7198 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-pkexec-execution.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-pkexec-execution.md @@ -121,10 +121,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5418] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-host.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-host.md index 99a8c55cef..855827559b 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-host.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-host.md @@ -95,9 +95,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-parent-process.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-parent-process.md index 551e92f18c..4d14bde759 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-parent-process.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-parent-process.md @@ -97,9 +97,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-user.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-user.md index 1a6d8bdf75..c0ecafc9b5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-user.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-unusual-process-spawned-by-a-user.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-virtual-machine-fingerprinting.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-virtual-machine-fingerprinting.md index fa5b5345b5..4f7dc77283 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-virtual-machine-fingerprinting.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-17-4-virtual-machine-fingerprinting.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_5376] diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-hosts-file-modified.md index 7c581f34c4..99d6dfd206 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-inbound-connection-to-an-unsecure-elasticsearch-node.md index 0de15a1f53..91eb9d79b6 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-2-1-inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -29,7 +29,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-hosts-file-modified.md index 27e38704ca..0ad29dd9c6 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-filebeat-module-v8-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-filebeat-module-v8-x-indicator-match.md index 292fbb763f..a0b3c2ef20 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-filebeat-module-v8-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-filebeat-module-v8-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v8 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-indicator-match.md index e906eb0fe6..6be5b1efe9 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-2-threat-intel-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel integrations have a **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-default-cobalt-strike-team-server-certificate.md index cad7680327..4848e1f79b 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) * [https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack](https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-hosts-file-modified.md index 20fa0aa19a..c849d1ab4b 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-inbound-connection-to-an-unsecure-elasticsearch-node.md index 1915aea54a..f7f87a14b5 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -29,7 +29,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-filebeat-module-v8-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-filebeat-module-v8-x-indicator-match.md index b7fd961333..f9995c82a3 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-filebeat-module-v8-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-filebeat-module-v8-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v8 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-indicator-match.md index 5fa03c60fa..4a4fdebea2 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-3-3-threat-intel-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel integrations have a **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-default-cobalt-strike-team-server-certificate.md index 63d726acfe..e961259240 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) * [https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack](https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-hosts-file-modified.md index 059aae3da5..d404ffdf83 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-filebeat-module-v8-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-filebeat-module-v8-x-indicator-match.md index ce9503ebcd..fcc373099a 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-filebeat-module-v8-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-filebeat-module-v8-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v8 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-indicator-match.md index 5c9d28b1d5..98ce4f9744 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-1-threat-intel-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel integrations have a **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-default-cobalt-strike-team-server-certificate.md index 54450b6cf5..1dd0ced89f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) * [https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack](https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack) diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-hosts-file-modified.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-hosts-file-modified.md index ad6469d8e4..b9801120d3 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-hosts-file-modified.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-inbound-connection-to-an-unsecure-elasticsearch-node.md index e8fce42148..fe1dc666fc 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -29,7 +29,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-filebeat-module-v8-x-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-filebeat-module-v8-x-indicator-match.md index d9a13c9b9b..c8859c8bec 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-filebeat-module-v8-x-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-filebeat-module-v8-x-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel Filebeat module (v8 **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-indicator-match.md b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-indicator-match.md index 45eb25335b..d63770c18f 100644 --- a/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-indicator-match.md +++ b/docs/reference/prebuilt-rules-downloadable-updates/prebuilt-rule-8-4-2-threat-intel-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when indicators from the Threat Intel integrations have a **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) **Tags**: diff --git a/docs/reference/prebuilt-rules/application-added-to-google-workspace-domain.md b/docs/reference/prebuilt-rules/application-added-to-google-workspace-domain.md index ab8a5b12e4..d78fcf42a8 100644 --- a/docs/reference/prebuilt-rules/application-added-to-google-workspace-domain.md +++ b/docs/reference/prebuilt-rules/application-added-to-google-workspace-domain.md @@ -99,7 +99,7 @@ This rule checks for applications that were manually added to the Marketplace by * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_78] diff --git a/docs/reference/prebuilt-rules/application-removed-from-blocklist-in-google-workspace.md b/docs/reference/prebuilt-rules/application-removed-from-blocklist-in-google-workspace.md index b543b030c4..4445783d5c 100644 --- a/docs/reference/prebuilt-rules/application-removed-from-blocklist-in-google-workspace.md +++ b/docs/reference/prebuilt-rules/application-removed-from-blocklist-in-google-workspace.md @@ -99,7 +99,7 @@ This rule identifies a Marketplace blocklist update that consists of a Google Wo * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_79] diff --git a/docs/reference/prebuilt-rules/attempt-to-disable-syslog-service.md b/docs/reference/prebuilt-rules/attempt-to-disable-syslog-service.md index 2a23e569ea..ef57ff1234 100644 --- a/docs/reference/prebuilt-rules/attempt-to-disable-syslog-service.md +++ b/docs/reference/prebuilt-rules/attempt-to-disable-syslog-service.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_158] diff --git a/docs/reference/prebuilt-rules/base16-or-base32-encoding-decoding-activity.md b/docs/reference/prebuilt-rules/base16-or-base32-encoding-decoding-activity.md index 6e84c566d2..3e1149d588 100644 --- a/docs/reference/prebuilt-rules/base16-or-base32-encoding-decoding-activity.md +++ b/docs/reference/prebuilt-rules/base16-or-base32-encoding-decoding-activity.md @@ -123,10 +123,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_214] diff --git a/docs/reference/prebuilt-rules/connection-to-external-network-via-telnet.md b/docs/reference/prebuilt-rules/connection-to-external-network-via-telnet.md index 11ff420ad8..604d8e1e6e 100644 --- a/docs/reference/prebuilt-rules/connection-to-external-network-via-telnet.md +++ b/docs/reference/prebuilt-rules/connection-to-external-network-via-telnet.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_241] diff --git a/docs/reference/prebuilt-rules/connection-to-internal-network-via-telnet.md b/docs/reference/prebuilt-rules/connection-to-internal-network-via-telnet.md index 11d83168af..2b4a7001be 100644 --- a/docs/reference/prebuilt-rules/connection-to-internal-network-via-telnet.md +++ b/docs/reference/prebuilt-rules/connection-to-internal-network-via-telnet.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_242] diff --git a/docs/reference/prebuilt-rules/creation-of-hidden-files-and-directories-via-commandline.md b/docs/reference/prebuilt-rules/creation-of-hidden-files-and-directories-via-commandline.md index aed995e24b..45cec3b9b9 100644 --- a/docs/reference/prebuilt-rules/creation-of-hidden-files-and-directories-via-commandline.md +++ b/docs/reference/prebuilt-rules/creation-of-hidden-files-and-directories-via-commandline.md @@ -114,10 +114,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/creation-of-hidden-shared-object-file.md b/docs/reference/prebuilt-rules/creation-of-hidden-shared-object-file.md index 3698ec7236..52a0b6078b 100644 --- a/docs/reference/prebuilt-rules/creation-of-hidden-shared-object-file.md +++ b/docs/reference/prebuilt-rules/creation-of-hidden-shared-object-file.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/default-cobalt-strike-team-server-certificate.md b/docs/reference/prebuilt-rules/default-cobalt-strike-team-server-certificate.md index 15f82c9bcd..0d20b6a90b 100644 --- a/docs/reference/prebuilt-rules/default-cobalt-strike-team-server-certificate.md +++ b/docs/reference/prebuilt-rules/default-cobalt-strike-team-server-certificate.md @@ -30,7 +30,7 @@ This rule detects the use of the default Cobalt Strike Team Server TLS certifica * [https://attack.mitre.org/software/S0154/](https://attack.mitre.org/software/S0154/) * [https://www.cobaltstrike.com/help-setup-collaboration](https://www.cobaltstrike.com/help-setup-collaboration) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://docs/reference/packetbeat/configuration-tls.md) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/configuration-tls.md](beats://reference/packetbeat/configuration-tls.md) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-suricata.html) * [https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html](https://www.elastic.co/guide/en/beats/filebeat/7.9/filebeat-module-zeek.html) * [https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack](https://www.elastic.co/security-labs/collecting-cobalt-strike-beacons-with-the-elastic-stack) diff --git a/docs/reference/prebuilt-rules/domain-added-to-google-workspace-trusted-domains.md b/docs/reference/prebuilt-rules/domain-added-to-google-workspace-trusted-domains.md index 06a5f1a235..aec45180b4 100644 --- a/docs/reference/prebuilt-rules/domain-added-to-google-workspace-trusted-domains.md +++ b/docs/reference/prebuilt-rules/domain-added-to-google-workspace-trusted-domains.md @@ -96,7 +96,7 @@ This rule detects when a third-party domain is added to the list of trusted doma * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_176] diff --git a/docs/reference/prebuilt-rules/external-user-added-to-google-workspace-group.md b/docs/reference/prebuilt-rules/external-user-added-to-google-workspace-group.md index 55bddd18bd..5dc7923a9d 100644 --- a/docs/reference/prebuilt-rules/external-user-added-to-google-workspace-group.md +++ b/docs/reference/prebuilt-rules/external-user-added-to-google-workspace-group.md @@ -102,7 +102,7 @@ This rule identifies when an external user account is added to an organization * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_204] diff --git a/docs/reference/prebuilt-rules/file-made-immutable-by-chattr.md b/docs/reference/prebuilt-rules/file-made-immutable-by-chattr.md index 7e6c5f1d55..ab385f6122 100644 --- a/docs/reference/prebuilt-rules/file-made-immutable-by-chattr.md +++ b/docs/reference/prebuilt-rules/file-made-immutable-by-chattr.md @@ -118,10 +118,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/file-permission-modification-in-writable-directory.md b/docs/reference/prebuilt-rules/file-permission-modification-in-writable-directory.md index 312de140c0..163b0b341a 100644 --- a/docs/reference/prebuilt-rules/file-permission-modification-in-writable-directory.md +++ b/docs/reference/prebuilt-rules/file-permission-modification-in-writable-directory.md @@ -113,10 +113,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_353] diff --git a/docs/reference/prebuilt-rules/file-transfer-or-listener-established-via-netcat.md b/docs/reference/prebuilt-rules/file-transfer-or-listener-established-via-netcat.md index 6dbe3717b8..0136968193 100644 --- a/docs/reference/prebuilt-rules/file-transfer-or-listener-established-via-netcat.md +++ b/docs/reference/prebuilt-rules/file-transfer-or-listener-established-via-netcat.md @@ -128,10 +128,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_356] diff --git a/docs/reference/prebuilt-rules/first-time-seen-google-workspace-oauth-login-from-third-party-application.md b/docs/reference/prebuilt-rules/first-time-seen-google-workspace-oauth-login-from-third-party-application.md index 5d86969892..42c3e3de24 100644 --- a/docs/reference/prebuilt-rules/first-time-seen-google-workspace-oauth-login-from-third-party-application.md +++ b/docs/reference/prebuilt-rules/first-time-seen-google-workspace-oauth-login-from-third-party-application.md @@ -92,7 +92,7 @@ OAuth is a protocol that allows third-party applications to access user data wit * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_214] diff --git a/docs/reference/prebuilt-rules/google-drive-ownership-transferred-via-google-workspace.md b/docs/reference/prebuilt-rules/google-drive-ownership-transferred-via-google-workspace.md index 7379de9808..1472878d03 100644 --- a/docs/reference/prebuilt-rules/google-drive-ownership-transferred-via-google-workspace.md +++ b/docs/reference/prebuilt-rules/google-drive-ownership-transferred-via-google-workspace.md @@ -95,7 +95,7 @@ This rule identifies when the ownership of a shared drive within a Google Worksp * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_246] diff --git a/docs/reference/prebuilt-rules/google-workspace-2sv-policy-disabled.md b/docs/reference/prebuilt-rules/google-workspace-2sv-policy-disabled.md index b9b645330d..23e4122056 100644 --- a/docs/reference/prebuilt-rules/google-workspace-2sv-policy-disabled.md +++ b/docs/reference/prebuilt-rules/google-workspace-2sv-policy-disabled.md @@ -97,7 +97,7 @@ This rule detects when a 2SV policy is disabled in Google Workspace. * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_247] diff --git a/docs/reference/prebuilt-rules/google-workspace-admin-role-assigned-to-a-user.md b/docs/reference/prebuilt-rules/google-workspace-admin-role-assigned-to-a-user.md index d8d4f4c702..19e1a6ae53 100644 --- a/docs/reference/prebuilt-rules/google-workspace-admin-role-assigned-to-a-user.md +++ b/docs/reference/prebuilt-rules/google-workspace-admin-role-assigned-to-a-user.md @@ -101,7 +101,7 @@ This rule identifies when a Google Workspace administrative role is assigned to * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_249] diff --git a/docs/reference/prebuilt-rules/google-workspace-admin-role-deletion.md b/docs/reference/prebuilt-rules/google-workspace-admin-role-deletion.md index 9a7c7f4bbc..4ef6ed8052 100644 --- a/docs/reference/prebuilt-rules/google-workspace-admin-role-deletion.md +++ b/docs/reference/prebuilt-rules/google-workspace-admin-role-deletion.md @@ -96,7 +96,7 @@ This rule identifies when a Google Workspace administrative role is deleted with * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_250] diff --git a/docs/reference/prebuilt-rules/google-workspace-api-access-granted-via-domain-wide-delegation.md b/docs/reference/prebuilt-rules/google-workspace-api-access-granted-via-domain-wide-delegation.md index 46cc33ea8a..5d96200f4d 100644 --- a/docs/reference/prebuilt-rules/google-workspace-api-access-granted-via-domain-wide-delegation.md +++ b/docs/reference/prebuilt-rules/google-workspace-api-access-granted-via-domain-wide-delegation.md @@ -97,7 +97,7 @@ This rule identifies when an application is authorized API client access. * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_248] diff --git a/docs/reference/prebuilt-rules/google-workspace-bitlocker-setting-disabled.md b/docs/reference/prebuilt-rules/google-workspace-bitlocker-setting-disabled.md index 358b048c52..0c4360cd10 100644 --- a/docs/reference/prebuilt-rules/google-workspace-bitlocker-setting-disabled.md +++ b/docs/reference/prebuilt-rules/google-workspace-bitlocker-setting-disabled.md @@ -94,7 +94,7 @@ This rule identifies a user with administrative privileges and access to the adm * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_251] diff --git a/docs/reference/prebuilt-rules/google-workspace-custom-admin-role-created.md b/docs/reference/prebuilt-rules/google-workspace-custom-admin-role-created.md index 9139db9fd0..79dcde91cd 100644 --- a/docs/reference/prebuilt-rules/google-workspace-custom-admin-role-created.md +++ b/docs/reference/prebuilt-rules/google-workspace-custom-admin-role-created.md @@ -101,7 +101,7 @@ This rule identifies when a Google Workspace administrative role is added within * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_252] diff --git a/docs/reference/prebuilt-rules/google-workspace-custom-gmail-route-created-or-modified.md b/docs/reference/prebuilt-rules/google-workspace-custom-gmail-route-created-or-modified.md index ca0a557a21..a607d9a830 100644 --- a/docs/reference/prebuilt-rules/google-workspace-custom-gmail-route-created-or-modified.md +++ b/docs/reference/prebuilt-rules/google-workspace-custom-gmail-route-created-or-modified.md @@ -94,7 +94,7 @@ This rule identifies the creation of a custom global Gmail route by an administr * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_253] diff --git a/docs/reference/prebuilt-rules/google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md b/docs/reference/prebuilt-rules/google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md index e8ca9584aa..95b23256ad 100644 --- a/docs/reference/prebuilt-rules/google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md +++ b/docs/reference/prebuilt-rules/google-workspace-drive-encryption-key-s-accessed-from-anonymous-user.md @@ -90,7 +90,7 @@ Google Workspace Drive allows users to store and share files, including sensitiv * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_254] diff --git a/docs/reference/prebuilt-rules/google-workspace-mfa-enforcement-disabled.md b/docs/reference/prebuilt-rules/google-workspace-mfa-enforcement-disabled.md index de6b8622f5..1aa9d863c8 100644 --- a/docs/reference/prebuilt-rules/google-workspace-mfa-enforcement-disabled.md +++ b/docs/reference/prebuilt-rules/google-workspace-mfa-enforcement-disabled.md @@ -97,7 +97,7 @@ This rule identifies the disabling of MFA enforcement in Google Workspace. This * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_255] diff --git a/docs/reference/prebuilt-rules/google-workspace-object-copied-to-external-drive-with-app-consent.md b/docs/reference/prebuilt-rules/google-workspace-object-copied-to-external-drive-with-app-consent.md index b621aa8701..6e305a0535 100644 --- a/docs/reference/prebuilt-rules/google-workspace-object-copied-to-external-drive-with-app-consent.md +++ b/docs/reference/prebuilt-rules/google-workspace-object-copied-to-external-drive-with-app-consent.md @@ -102,7 +102,7 @@ This rule aims to detect when a user copies an external Drive object to their Dr * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_256] diff --git a/docs/reference/prebuilt-rules/google-workspace-password-policy-modified.md b/docs/reference/prebuilt-rules/google-workspace-password-policy-modified.md index 7d29f5e19e..95cc392853 100644 --- a/docs/reference/prebuilt-rules/google-workspace-password-policy-modified.md +++ b/docs/reference/prebuilt-rules/google-workspace-password-policy-modified.md @@ -99,7 +99,7 @@ This rule detects when a Google Workspace password policy is modified to decreas * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_257] diff --git a/docs/reference/prebuilt-rules/google-workspace-restrictions-for-marketplace-modified-to-allow-any-app.md b/docs/reference/prebuilt-rules/google-workspace-restrictions-for-marketplace-modified-to-allow-any-app.md index 9776cfae5c..cd0ca56859 100644 --- a/docs/reference/prebuilt-rules/google-workspace-restrictions-for-marketplace-modified-to-allow-any-app.md +++ b/docs/reference/prebuilt-rules/google-workspace-restrictions-for-marketplace-modified-to-allow-any-app.md @@ -100,7 +100,7 @@ This rule identifies when the global allow-all setting is enabled for Google Wor * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_258] diff --git a/docs/reference/prebuilt-rules/google-workspace-role-modified.md b/docs/reference/prebuilt-rules/google-workspace-role-modified.md index 5459922e38..39e81f8e5f 100644 --- a/docs/reference/prebuilt-rules/google-workspace-role-modified.md +++ b/docs/reference/prebuilt-rules/google-workspace-role-modified.md @@ -103,7 +103,7 @@ This rule identifies when a Google Workspace role is modified. * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_259] diff --git a/docs/reference/prebuilt-rules/google-workspace-suspended-user-account-renewed.md b/docs/reference/prebuilt-rules/google-workspace-suspended-user-account-renewed.md index 0cf20205a8..f9cbc1196a 100644 --- a/docs/reference/prebuilt-rules/google-workspace-suspended-user-account-renewed.md +++ b/docs/reference/prebuilt-rules/google-workspace-suspended-user-account-renewed.md @@ -87,7 +87,7 @@ Google Workspace manages user identities and access, crucial for organizational * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_260] diff --git a/docs/reference/prebuilt-rules/google-workspace-user-organizational-unit-changed.md b/docs/reference/prebuilt-rules/google-workspace-user-organizational-unit-changed.md index 9f70510978..21166f0b57 100644 --- a/docs/reference/prebuilt-rules/google-workspace-user-organizational-unit-changed.md +++ b/docs/reference/prebuilt-rules/google-workspace-user-organizational-unit-changed.md @@ -100,7 +100,7 @@ This rule identifies when a user has been moved to a different organizational un * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_261] diff --git a/docs/reference/prebuilt-rules/hosts-file-modified.md b/docs/reference/prebuilt-rules/hosts-file-modified.md index fe4a4d46a2..b3e9acd6c6 100644 --- a/docs/reference/prebuilt-rules/hosts-file-modified.md +++ b/docs/reference/prebuilt-rules/hosts-file-modified.md @@ -28,7 +28,7 @@ The hosts file on endpoints is used to control manual IP address to hostname res **References**: -* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://docs/reference/auditbeat/auditbeat-reference-yml.md) +* [/beats/docs/reference/ingestion-tools/beats-auditbeat/auditbeat-reference-yml.md](beats://reference/auditbeat/auditbeat-reference-yml.md) **Tags**: diff --git a/docs/reference/prebuilt-rules/hping-process-activity.md b/docs/reference/prebuilt-rules/hping-process-activity.md index e8a1dfd8dd..8982a570ca 100644 --- a/docs/reference/prebuilt-rules/hping-process-activity.md +++ b/docs/reference/prebuilt-rules/hping-process-activity.md @@ -125,10 +125,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_450] diff --git a/docs/reference/prebuilt-rules/inbound-connection-to-an-unsecure-elasticsearch-node.md b/docs/reference/prebuilt-rules/inbound-connection-to-an-unsecure-elasticsearch-node.md index 8b47ef5a04..7b45b106e8 100644 --- a/docs/reference/prebuilt-rules/inbound-connection-to-an-unsecure-elasticsearch-node.md +++ b/docs/reference/prebuilt-rules/inbound-connection-to-an-unsecure-elasticsearch-node.md @@ -27,7 +27,7 @@ Identifies Elasticsearch nodes that do not have Transport Layer Security (TLS), **References**: * [docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md](docs-content://deploy-manage/deploy/self-managed/installing-elasticsearch.md) -* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://docs/reference/packetbeat/packetbeat-http-options.md#_send_all_headers) +* [/beats/docs/reference/ingestion-tools/beats-packetbeat/packetbeat-http-options.md#_send_all_headers](beats://reference/packetbeat/packetbeat-http-options.md#_send_all_headers) **Tags**: diff --git a/docs/reference/prebuilt-rules/interactive-terminal-spawned-via-perl.md b/docs/reference/prebuilt-rules/interactive-terminal-spawned-via-perl.md index 11e0ac2fa3..23605f9417 100644 --- a/docs/reference/prebuilt-rules/interactive-terminal-spawned-via-perl.md +++ b/docs/reference/prebuilt-rules/interactive-terminal-spawned-via-perl.md @@ -116,10 +116,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_474] diff --git a/docs/reference/prebuilt-rules/linux-group-creation.md b/docs/reference/prebuilt-rules/linux-group-creation.md index 1ebda3d019..5c93d2ce14 100644 --- a/docs/reference/prebuilt-rules/linux-group-creation.md +++ b/docs/reference/prebuilt-rules/linux-group-creation.md @@ -104,17 +104,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_509] diff --git a/docs/reference/prebuilt-rules/linux-user-account-creation.md b/docs/reference/prebuilt-rules/linux-user-account-creation.md index ca7f8514d4..3868ee3159 100644 --- a/docs/reference/prebuilt-rules/linux-user-account-creation.md +++ b/docs/reference/prebuilt-rules/linux-user-account-creation.md @@ -103,17 +103,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_515] diff --git a/docs/reference/prebuilt-rules/login-via-unusual-system-user.md b/docs/reference/prebuilt-rules/login-via-unusual-system-user.md index a2c74f32f7..cbebe1a615 100644 --- a/docs/reference/prebuilt-rules/login-via-unusual-system-user.md +++ b/docs/reference/prebuilt-rules/login-via-unusual-system-user.md @@ -97,17 +97,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_521] diff --git a/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md b/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md index 1935786118..7f574b7313 100644 --- a/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md +++ b/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-predicted-to-be-a-dga-domain.md @@ -100,10 +100,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md b/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md index fc8dec177b..2e25835421 100644 --- a/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md +++ b/docs/reference/prebuilt-rules/machine-learning-detected-a-dns-request-with-a-high-dga-probability-score.md @@ -99,10 +99,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md b/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md index 7b0dc4c140..9263211521 100644 --- a/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md +++ b/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-high-malicious-probability-score.md @@ -101,9 +101,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md b/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md index 35773d2cf8..db615cc5b6 100644 --- a/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md +++ b/docs/reference/prebuilt-rules/machine-learning-detected-a-suspicious-windows-event-with-a-low-malicious-probability-score.md @@ -101,9 +101,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md b/docs/reference/prebuilt-rules/machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md index 7cc08d6b5e..bab84984c9 100644 --- a/docs/reference/prebuilt-rules/machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md +++ b/docs/reference/prebuilt-rules/machine-learning-detected-dga-activity-using-a-known-sunburst-dns-domain.md @@ -100,10 +100,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules/mfa-disabled-for-google-workspace-organization.md b/docs/reference/prebuilt-rules/mfa-disabled-for-google-workspace-organization.md index f588c67aae..9e6d07846f 100644 --- a/docs/reference/prebuilt-rules/mfa-disabled-for-google-workspace-organization.md +++ b/docs/reference/prebuilt-rules/mfa-disabled-for-google-workspace-organization.md @@ -97,7 +97,7 @@ This rule identifies when MFA enforcement is turned off in Google Workspace. Thi * By default, `var.interval` is set to 2 hours (2h). Consider changing this interval to a lower value, such as 10 minutes (10m). * See the following references for further information: * [https://support.google.com/a/answer/7061566](https://support.google.com/a/answer/7061566) -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://docs/reference/filebeat/filebeat-module-google_workspace.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-google_workspace.md](beats://reference/filebeat/filebeat-module-google_workspace.md) ## Setup [_setup_312] diff --git a/docs/reference/prebuilt-rules/modification-of-dynamic-linker-preload-shared-object.md b/docs/reference/prebuilt-rules/modification-of-dynamic-linker-preload-shared-object.md index e6fa05f4b3..9d8d8dbc56 100644 --- a/docs/reference/prebuilt-rules/modification-of-dynamic-linker-preload-shared-object.md +++ b/docs/reference/prebuilt-rules/modification-of-dynamic-linker-preload-shared-object.md @@ -119,10 +119,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_580] diff --git a/docs/reference/prebuilt-rules/modification-of-openssh-binaries.md b/docs/reference/prebuilt-rules/modification-of-openssh-binaries.md index 1aecb1f761..3b676b10ac 100644 --- a/docs/reference/prebuilt-rules/modification-of-openssh-binaries.md +++ b/docs/reference/prebuilt-rules/modification-of-openssh-binaries.md @@ -143,10 +143,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_583] diff --git a/docs/reference/prebuilt-rules/namespace-manipulation-using-unshare.md b/docs/reference/prebuilt-rules/namespace-manipulation-using-unshare.md index be1b847ba7..8d4075ce56 100644 --- a/docs/reference/prebuilt-rules/namespace-manipulation-using-unshare.md +++ b/docs/reference/prebuilt-rules/namespace-manipulation-using-unshare.md @@ -120,10 +120,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_609] diff --git a/docs/reference/prebuilt-rules/network-connections-initiated-through-xdg-autostart-entry.md b/docs/reference/prebuilt-rules/network-connections-initiated-through-xdg-autostart-entry.md index 5d69b926e7..7353e8858e 100644 --- a/docs/reference/prebuilt-rules/network-connections-initiated-through-xdg-autostart-entry.md +++ b/docs/reference/prebuilt-rules/network-connections-initiated-through-xdg-autostart-entry.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/nping-process-activity.md b/docs/reference/prebuilt-rules/nping-process-activity.md index 04d2be7560..8deb0551a6 100644 --- a/docs/reference/prebuilt-rules/nping-process-activity.md +++ b/docs/reference/prebuilt-rules/nping-process-activity.md @@ -125,10 +125,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_637] diff --git a/docs/reference/prebuilt-rules/persistence-via-kde-autostart-script-or-desktop-file-modification.md b/docs/reference/prebuilt-rules/persistence-via-kde-autostart-script-or-desktop-file-modification.md index d1cb952f31..b2a9c2b6eb 100644 --- a/docs/reference/prebuilt-rules/persistence-via-kde-autostart-script-or-desktop-file-modification.md +++ b/docs/reference/prebuilt-rules/persistence-via-kde-autostart-script-or-desktop-file-modification.md @@ -149,10 +149,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/potential-dga-activity.md b/docs/reference/prebuilt-rules/potential-dga-activity.md index 6fbe237778..deffa086f8 100644 --- a/docs/reference/prebuilt-rules/potential-dga-activity.md +++ b/docs/reference/prebuilt-rules/potential-dga-activity.md @@ -93,10 +93,10 @@ The DGA Detection integration consists of an ML-based framework to detect DGA ac * Fleet is required for DGA Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://docs/reference/packetbeat/packetbeat-overview.md). +* DNS events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint), [Network Packet Capture](https://docs.elastic.co/integrations/network_traffic) integration, or [Packetbeat](beats://reference/packetbeat/packetbeat-overview.md). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). * To add the Network Packet Capture integration to an Elastic Agent policy, refer to [this](docs-content://reference/ingestion-tools/fleet/add-integration-to-policy.md) guide. -* To set up and run Packetbeat, follow [this](beats://docs/reference/packetbeat/setting-up-running.md) guide. +* To set up and run Packetbeat, follow [this](beats://reference/packetbeat/setting-up-running.md) guide. **The following steps should be executed to install assets associated with the DGA Detection integration:** diff --git a/docs/reference/prebuilt-rules/potential-disabling-of-selinux.md b/docs/reference/prebuilt-rules/potential-disabling-of-selinux.md index d8eac1773b..9cc979cd4b 100644 --- a/docs/reference/prebuilt-rules/potential-disabling-of-selinux.md +++ b/docs/reference/prebuilt-rules/potential-disabling-of-selinux.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_715] diff --git a/docs/reference/prebuilt-rules/potential-external-linux-ssh-brute-force-detected.md b/docs/reference/prebuilt-rules/potential-external-linux-ssh-brute-force-detected.md index 27b0c68547..dfa863c5cf 100644 --- a/docs/reference/prebuilt-rules/potential-external-linux-ssh-brute-force-detected.md +++ b/docs/reference/prebuilt-rules/potential-external-linux-ssh-brute-force-detected.md @@ -95,17 +95,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_723] diff --git a/docs/reference/prebuilt-rules/potential-internal-linux-ssh-brute-force-detected.md b/docs/reference/prebuilt-rules/potential-internal-linux-ssh-brute-force-detected.md index 74cac106d1..96855a9381 100644 --- a/docs/reference/prebuilt-rules/potential-internal-linux-ssh-brute-force-detected.md +++ b/docs/reference/prebuilt-rules/potential-internal-linux-ssh-brute-force-detected.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_731] diff --git a/docs/reference/prebuilt-rules/potential-meterpreter-reverse-shell.md b/docs/reference/prebuilt-rules/potential-meterpreter-reverse-shell.md index 7167fcbbe8..6dc031724c 100644 --- a/docs/reference/prebuilt-rules/potential-meterpreter-reverse-shell.md +++ b/docs/reference/prebuilt-rules/potential-meterpreter-reverse-shell.md @@ -95,10 +95,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules/potential-openssh-backdoor-logging-activity.md b/docs/reference/prebuilt-rules/potential-openssh-backdoor-logging-activity.md index ea5f1fc5b3..9602f66716 100644 --- a/docs/reference/prebuilt-rules/potential-openssh-backdoor-logging-activity.md +++ b/docs/reference/prebuilt-rules/potential-openssh-backdoor-logging-activity.md @@ -123,10 +123,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/potential-protocol-tunneling-via-earthworm.md b/docs/reference/prebuilt-rules/potential-protocol-tunneling-via-earthworm.md index db7def9a4f..918c0ef687 100644 --- a/docs/reference/prebuilt-rules/potential-protocol-tunneling-via-earthworm.md +++ b/docs/reference/prebuilt-rules/potential-protocol-tunneling-via-earthworm.md @@ -148,10 +148,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/potential-reverse-shell-via-udp.md b/docs/reference/prebuilt-rules/potential-reverse-shell-via-udp.md index 8f93407808..88fa020905 100644 --- a/docs/reference/prebuilt-rules/potential-reverse-shell-via-udp.md +++ b/docs/reference/prebuilt-rules/potential-reverse-shell-via-udp.md @@ -97,10 +97,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules/potential-successful-linux-ftp-brute-force-attack-detected.md b/docs/reference/prebuilt-rules/potential-successful-linux-ftp-brute-force-attack-detected.md index 51985e0190..8028f62fd8 100644 --- a/docs/reference/prebuilt-rules/potential-successful-linux-ftp-brute-force-attack-detected.md +++ b/docs/reference/prebuilt-rules/potential-successful-linux-ftp-brute-force-attack-detected.md @@ -91,10 +91,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules/potential-successful-linux-rdp-brute-force-attack-detected.md b/docs/reference/prebuilt-rules/potential-successful-linux-rdp-brute-force-attack-detected.md index 5c4f9d1319..1921945de5 100644 --- a/docs/reference/prebuilt-rules/potential-successful-linux-rdp-brute-force-attack-detected.md +++ b/docs/reference/prebuilt-rules/potential-successful-linux-rdp-brute-force-attack-detected.md @@ -92,10 +92,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Auditd Manager Integration Setup** diff --git a/docs/reference/prebuilt-rules/potential-successful-ssh-brute-force-attack.md b/docs/reference/prebuilt-rules/potential-successful-ssh-brute-force-attack.md index 4f25812ef3..fe2046b3a8 100644 --- a/docs/reference/prebuilt-rules/potential-successful-ssh-brute-force-attack.md +++ b/docs/reference/prebuilt-rules/potential-successful-ssh-brute-force-attack.md @@ -88,10 +88,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Filebeat Setup** @@ -100,17 +100,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the “Filebeat System Module” to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_825] diff --git a/docs/reference/prebuilt-rules/process-backgrounded-by-unusual-parent.md b/docs/reference/prebuilt-rules/process-backgrounded-by-unusual-parent.md index c79a824090..63fae4c6db 100644 --- a/docs/reference/prebuilt-rules/process-backgrounded-by-unusual-parent.md +++ b/docs/reference/prebuilt-rules/process-backgrounded-by-unusual-parent.md @@ -120,10 +120,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_882] diff --git a/docs/reference/prebuilt-rules/process-started-with-executable-stack.md b/docs/reference/prebuilt-rules/process-started-with-executable-stack.md index 910116db45..1a5ceeb99a 100644 --- a/docs/reference/prebuilt-rules/process-started-with-executable-stack.md +++ b/docs/reference/prebuilt-rules/process-started-with-executable-stack.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_896] diff --git a/docs/reference/prebuilt-rules/rapid7-threat-command-cves-correlation.md b/docs/reference/prebuilt-rules/rapid7-threat-command-cves-correlation.md index 0ebe4f8ef5..dae3892f64 100644 --- a/docs/reference/prebuilt-rules/rapid7-threat-command-cves-correlation.md +++ b/docs/reference/prebuilt-rules/rapid7-threat-command-cves-correlation.md @@ -30,7 +30,7 @@ This rule is triggered when CVEs collected from the Rapid7 Threat Command Integr **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [https://docs.elastic.co/integrations/ti_rapid7_threat_command](https://docs.elastic.co/integrations/ti_rapid7_threat_command) **Tags**: diff --git a/docs/reference/prebuilt-rules/segfault-detected.md b/docs/reference/prebuilt-rules/segfault-detected.md index 82de2255c1..92c1ac98a8 100644 --- a/docs/reference/prebuilt-rules/segfault-detected.md +++ b/docs/reference/prebuilt-rules/segfault-detected.md @@ -54,17 +54,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_970] diff --git a/docs/reference/prebuilt-rules/sensitive-files-compression.md b/docs/reference/prebuilt-rules/sensitive-files-compression.md index fc7e99df3d..f509cd4944 100644 --- a/docs/reference/prebuilt-rules/sensitive-files-compression.md +++ b/docs/reference/prebuilt-rules/sensitive-files-compression.md @@ -119,10 +119,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_972] diff --git a/docs/reference/prebuilt-rules/suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md b/docs/reference/prebuilt-rules/suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md index 0a69af3f7f..61f9328444 100644 --- a/docs/reference/prebuilt-rules/suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md +++ b/docs/reference/prebuilt-rules/suspicious-network-activity-to-the-internet-by-previously-unknown-executable.md @@ -140,10 +140,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Filebeat Setup** @@ -152,11 +152,11 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete “Setup and Run Filebeat” information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Packetbeat Setup** @@ -165,10 +165,10 @@ Packetbeat is a real-time network packet analyzer that you can use for applicati **The following steps should be executed in order to add the Packetbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/packetbeat/setup-repositories.md). -* To run Packetbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/packetbeat/running-on-docker.md). -* For quick start information for Packetbeat refer to the [helper guide](beats://docs/reference/packetbeat/packetbeat-installation-configuration.md). -* For complete “Setup and Run Packetbeat” information refer to the [helper guide](beats://docs/reference/packetbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/packetbeat/setup-repositories.md). +* To run Packetbeat on Docker follow the setup instructions in the [helper guide](beats://reference/packetbeat/running-on-docker.md). +* For quick start information for Packetbeat refer to the [helper guide](beats://reference/packetbeat/packetbeat-installation-configuration.md). +* For complete “Setup and Run Packetbeat” information refer to the [helper guide](beats://reference/packetbeat/setting-up-running.md). ## Rule query [_rule_query_1060] diff --git a/docs/reference/prebuilt-rules/suspicious-rc-local-error-message.md b/docs/reference/prebuilt-rules/suspicious-rc-local-error-message.md index 0cb0ccf662..ee95dcb768 100644 --- a/docs/reference/prebuilt-rules/suspicious-rc-local-error-message.md +++ b/docs/reference/prebuilt-rules/suspicious-rc-local-error-message.md @@ -94,17 +94,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_1103] diff --git a/docs/reference/prebuilt-rules/suspicious-usage-of-bpf-probe-write-user-helper.md b/docs/reference/prebuilt-rules/suspicious-usage-of-bpf-probe-write-user-helper.md index 1656be7b98..ade3349e5c 100644 --- a/docs/reference/prebuilt-rules/suspicious-usage-of-bpf-probe-write-user-helper.md +++ b/docs/reference/prebuilt-rules/suspicious-usage-of-bpf-probe-write-user-helper.md @@ -92,17 +92,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_1091] diff --git a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-host.md b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-host.md index 57caca4694..b0ec0d09bc 100644 --- a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-host.md +++ b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-host.md @@ -94,9 +94,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-parent-process.md b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-parent-process.md index 8fe9283a41..109a26d476 100644 --- a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-parent-process.md +++ b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-parent-process.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-user.md b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-user.md index 19bd6c2aee..0654955da1 100644 --- a/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-user.md +++ b/docs/reference/prebuilt-rules/suspicious-windows-process-cluster-spawned-by-a-user.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/system-log-file-deletion.md b/docs/reference/prebuilt-rules/system-log-file-deletion.md index 663ee633af..e7c59053ac 100644 --- a/docs/reference/prebuilt-rules/system-log-file-deletion.md +++ b/docs/reference/prebuilt-rules/system-log-file-deletion.md @@ -122,10 +122,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). **Custom Ingest Pipeline** diff --git a/docs/reference/prebuilt-rules/tainted-kernel-module-load.md b/docs/reference/prebuilt-rules/tainted-kernel-module-load.md index 5f0fcdb1d5..f994130e71 100644 --- a/docs/reference/prebuilt-rules/tainted-kernel-module-load.md +++ b/docs/reference/prebuilt-rules/tainted-kernel-module-load.md @@ -91,17 +91,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_1126] diff --git a/docs/reference/prebuilt-rules/tainted-out-of-tree-kernel-module-load.md b/docs/reference/prebuilt-rules/tainted-out-of-tree-kernel-module-load.md index 062d9a95a5..eccf635db2 100644 --- a/docs/reference/prebuilt-rules/tainted-out-of-tree-kernel-module-load.md +++ b/docs/reference/prebuilt-rules/tainted-out-of-tree-kernel-module-load.md @@ -92,17 +92,17 @@ Filebeat is a lightweight shipper for forwarding and centralizing log data. Inst **The following steps should be executed in order to add the Filebeat for the Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/filebeat/setup-repositories.md). -* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-docker.md). -* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/running-on-kubernetes.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/filebeat/setup-repositories.md). +* To run Filebeat on Docker follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-docker.md). +* To run Filebeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/filebeat/running-on-kubernetes.md). * For quick start information for Filebeat refer to the [helper guide](https://www.elastic.co/guide/en/beats/filebeat/8.11/filebeat-installation-configuration.html). -* For complete Setup and Run Filebeat information refer to the [helper guide](beats://docs/reference/filebeat/setting-up-running.md). +* For complete Setup and Run Filebeat information refer to the [helper guide](beats://reference/filebeat/setting-up-running.md). **Rule Specific Setup Note** * This rule requires the Filebeat System Module to be enabled. * The system module collects and parses logs created by the system logging service of common Unix/Linux based distributions. -* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://docs/reference/filebeat/filebeat-module-system.md). +* To run the system module of Filebeat on Linux follow the setup instructions in the [helper guide](beats://reference/filebeat/filebeat-module-system.md). ## Rule query [_rule_query_1127] diff --git a/docs/reference/prebuilt-rules/threat-intel-hash-indicator-match.md b/docs/reference/prebuilt-rules/threat-intel-hash-indicator-match.md index f039fba455..812c161829 100644 --- a/docs/reference/prebuilt-rules/threat-intel-hash-indicator-match.md +++ b/docs/reference/prebuilt-rules/threat-intel-hash-indicator-match.md @@ -29,7 +29,7 @@ This rule is triggered when a hash indicator from the Threat Intel Filebeat modu **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules/threat-intel-ip-address-indicator-match.md b/docs/reference/prebuilt-rules/threat-intel-ip-address-indicator-match.md index c60280bffd..20683532cc 100644 --- a/docs/reference/prebuilt-rules/threat-intel-ip-address-indicator-match.md +++ b/docs/reference/prebuilt-rules/threat-intel-ip-address-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when an IP address indicator from the Threat Intel Filebe **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules/threat-intel-url-indicator-match.md b/docs/reference/prebuilt-rules/threat-intel-url-indicator-match.md index 5311a49c29..88e3ac2b21 100644 --- a/docs/reference/prebuilt-rules/threat-intel-url-indicator-match.md +++ b/docs/reference/prebuilt-rules/threat-intel-url-indicator-match.md @@ -30,7 +30,7 @@ This rule is triggered when a URL indicator from the Threat Intel Filebeat modul **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules/threat-intel-windows-registry-indicator-match.md b/docs/reference/prebuilt-rules/threat-intel-windows-registry-indicator-match.md index 6c32dac47e..85c13ed889 100644 --- a/docs/reference/prebuilt-rules/threat-intel-windows-registry-indicator-match.md +++ b/docs/reference/prebuilt-rules/threat-intel-windows-registry-indicator-match.md @@ -29,7 +29,7 @@ This rule is triggered when a Windows registry indicator from the Threat Intel F **References**: -* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://docs/reference/filebeat/filebeat-module-threatintel.md) +* [/beats/docs/reference/ingestion-tools/beats-filebeat/filebeat-module-threatintel.md](beats://reference/filebeat/filebeat-module-threatintel.md) * [docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md](docs-content://solutions/security/get-started/enable-threat-intelligence-integrations.md) * [https://www.elastic.co/security/tip](https://www.elastic.co/security/tip) diff --git a/docs/reference/prebuilt-rules/unusual-pkexec-execution.md b/docs/reference/prebuilt-rules/unusual-pkexec-execution.md index 3538b65cf0..abb7f83ded 100644 --- a/docs/reference/prebuilt-rules/unusual-pkexec-execution.md +++ b/docs/reference/prebuilt-rules/unusual-pkexec-execution.md @@ -121,10 +121,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_1183] diff --git a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-host.md b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-host.md index 7b716e2191..9f5acd0393 100644 --- a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-host.md +++ b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-host.md @@ -95,9 +95,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-parent-process.md b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-parent-process.md index f4bf55ccc4..11ef67afcc 100644 --- a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-parent-process.md +++ b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-parent-process.md @@ -97,9 +97,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-user.md b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-user.md index 91584ab1d5..e1945dbd2a 100644 --- a/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-user.md +++ b/docs/reference/prebuilt-rules/unusual-process-spawned-by-a-user.md @@ -96,9 +96,9 @@ The LotL Attack Detection integration detects living-off-the-land activity in Wi * Fleet is required for LotL Attack Detection. * To configure Fleet Server refer to the [documentation](docs-content://reference/ingestion-tools/fleet/fleet-server.md). -* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://docs/reference/winlogbeat/_winlogbeat_overview.md)). +* Windows process events collected by the [Elastic Defend](https://docs.elastic.co/en/integrations/endpoint) integration or Winlogbeat([/beats/docs/reference/ingestion-tools/beats-winlogbeat/_winlogbeat_overview.md](beats://reference/winlogbeat/_winlogbeat_overview.md)). * To install Elastic Defend, refer to the [documentation](docs-content://solutions/security/configure-elastic-defend/install-elastic-defend.md). -* To set up and run Winlogbeat, follow [this](beats://docs/reference/winlogbeat/winlogbeat-installation-configuration.md) guide. +* To set up and run Winlogbeat, follow [this](beats://reference/winlogbeat/winlogbeat-installation-configuration.md) guide. **The following steps should be executed to install assets associated with the LotL Attack Detection integration:** diff --git a/docs/reference/prebuilt-rules/virtual-machine-fingerprinting.md b/docs/reference/prebuilt-rules/virtual-machine-fingerprinting.md index 68112c6d0f..69adfa1e4b 100644 --- a/docs/reference/prebuilt-rules/virtual-machine-fingerprinting.md +++ b/docs/reference/prebuilt-rules/virtual-machine-fingerprinting.md @@ -117,10 +117,10 @@ Auditbeat is a lightweight shipper that you can install on your servers to audit **The following steps should be executed in order to add the Auditbeat on a Linux System:** * Elastic provides repositories available for APT and YUM-based distributions. Note that we provide binary packages, but no source packages. -* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://docs/reference/auditbeat/setup-repositories.md). -* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-docker.md). -* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://docs/reference/auditbeat/running-on-kubernetes.md). -* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://docs/reference/auditbeat/setting-up-running.md). +* To install the APT and YUM repositories follow the setup instructions in this [helper guide](beats://reference/auditbeat/setup-repositories.md). +* To run Auditbeat on Docker follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-docker.md). +* To run Auditbeat on Kubernetes follow the setup instructions in the [helper guide](beats://reference/auditbeat/running-on-kubernetes.md). +* For complete “Setup and Run Auditbeat” information refer to the [helper guide](beats://reference/auditbeat/setting-up-running.md). ## Rule query [_rule_query_1204]