Skip to content

Quality of life updates to ProblemChild and DGA packages - #4829

Merged
susan-shu-c merged 6 commits into
mainfrom
update-problemchild-dga
Jan 17, 2023
Merged

Quality of life updates to ProblemChild and DGA packages#4829
susan-shu-c merged 6 commits into
mainfrom
update-problemchild-dga

Conversation

@susan-shu-c

@susan-shu-c susan-shu-c commented Dec 14, 2022

Copy link
Copy Markdown
Member

What does this PR do?

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Screenshots

@elasticmachine

elasticmachine commented Dec 14, 2022

Copy link
Copy Markdown

💚 Build Succeeded

the below badges are clickable and redirect to their specific view in the CI or DOCS
Pipeline View Test View Changes Artifacts preview preview

Expand to view the summary

Build stats

  • Start Time: 2023-01-11T23:24:42.576+0000

  • Duration: 15 min 23 sec

🤖 GitHub comments

Expand to view the GitHub comments

To re-run your PR in the CI, just comment with:

  • /test : Re-trigger the build.

@susan-shu-c
susan-shu-c requested a review from szeitlin December 15, 2022 14:52
@susan-shu-c
susan-shu-c marked this pull request as ready for review January 10, 2023 20:55
@susan-shu-c
susan-shu-c requested a review from a team as a code owner January 10, 2023 20:55

@alvarezmelissa87 alvarezmelissa87 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code LGTM ⚡

@susan-shu-c
susan-shu-c requested a review from ajosh0504 January 10, 2023 21:44
@ajosh0504

Copy link
Copy Markdown
Contributor

I want to clean up some tags, and add an ML tag to rules while we're at it. I'll get to this tomorrow.

@ajosh0504
ajosh0504 removed their request for review January 11, 2023 23:25
@ajosh0504

Copy link
Copy Markdown
Contributor

Screenshots from testing:

  • Changed package title LotL Attack Detection to Living off the Land Attack Detection

Screen Shot 2023-01-11 at 3 09 28 PM

  • Changed package title DGA Detection to Domain Generation Algorithm Detection

Screen Shot 2023-01-11 at 3 09 40 PM

  • ML job card title appears as Living off the Land Detection instead of ProblemChild

Screen Shot 2023-01-11 at 3 14 54 PM

  • Changed ML job group for ProblemChild from problem_child to living_off_the_land

Screen Shot 2023-01-11 at 3 15 07 PM

  • Updated/cleaned up tags for Living off the Land Attack Detection package. Also added the ML tag

Screen Shot 2023-01-11 at 3 20 28 PM

  • Updated/cleaned up tags for Domain Generation Algorithm Detection package. Also added the ML tag

Screen Shot 2023-01-11 at 3 20 44 PM

@ajosh0504

ajosh0504 commented Jan 11, 2023

Copy link
Copy Markdown
Contributor

@SourinPaul Can you please review the above screenshots and give a 👍 on the changes?

@ajosh0504

ajosh0504 commented Jan 11, 2023

Copy link
Copy Markdown
Contributor

@susan-shu-c I changed the Domain Generation Algorithm rule tags back to DGA for consistency (with the ML job module title, job groups etc.), and since DGA is a relatively well-known term. Plus we are defining it in the package description.

You good with that, or do you want to spell it out everywhere? I'm good with either.

cc: @SourinPaul

@susan-shu-c

susan-shu-c commented Jan 13, 2023

Copy link
Copy Markdown
Member Author

@ajosh0504

I changed the Domain Generation Algorithm rule tags back to DGA for consistency (with the ML job module title, job groups etc.), and since DGA is a relatively well-known term. Plus we are defining it in the package description.

I'm good that you changed it back, and agree that since it's in the package description, it'll be clear enough!

@SourinPaul

Copy link
Copy Markdown

Can you please review the above screenshots and give a 👍 on the changes?

@ajosh0504 @susan-shu-c, the changes look great. Thanks for the ping.

@susan-shu-c
susan-shu-c merged commit c1e91da into main Jan 17, 2023
@elasticmachine

Copy link
Copy Markdown

Package dga - 0.0.4 containing this change is available at https://epr.elastic.co/search?package=dga

@elasticmachine

Copy link
Copy Markdown

Package problemchild - 0.0.5 containing this change is available at https://epr.elastic.co/search?package=problemchild

orestisfl pushed a commit to orestisfl/integrations that referenced this pull request May 15, 2026
* Update from experimental to ga tag

* Update titles to explain acronyms

* Add dga to group id of ml job

* Spell out DGA full name in security rules

* Spell out LotL full name in ProblemChild security rules

* Cleaning up tags, ML job groups, doc updates

Co-authored-by: Apoorva <appujo@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

6 participants