diff --git a/source/release-notes/release_3_9_0.rst b/source/release-notes/release_3_9_0.rst index 51be4fcdbe..bf148c8604 100644 --- a/source/release-notes/release_3_9_0.rst +++ b/source/release-notes/release_3_9_0.rst @@ -7,9 +7,9 @@ This section shows the most relevant improvements and fixes in version 3.9.0. More details about these changes are provided in each component changelog: -- `wazuh/wazuh `_ -- `wazuh/wazuh-api `_ -- `wazuh/wazuh-ruleset `_ +- `wazuh/wazuh `_ +- `wazuh/wazuh-api `_ +- `wazuh/wazuh-ruleset `_ - `wazuh/wazuh-kibana-app `_ - `wazuh/wazuh-splunk `_ @@ -236,20 +236,20 @@ Wazuh ruleset - Improved rules for Docker to prevent the activation of certain rules that should not be activated. - Modified the structure and the names for Windows EventChannel fields in all the related rules. - Fixed the brute-force attack rules for Windows EventChannel by adding the new ```` option and changing some rules. -- Added *Sysmon rules* for Windows. +- Added *Sysmon rules* for Windows EventChannel. .. code-block:: xml - - 20350 - \\services.exe + + 61618 + \\services.exe Sysmon - Legitimate Parent Image - svchost.exe - + sysmon_event1 - lsm.exe + lsm.exe Sysmon - Suspicious Process - lsm.exe pci_dss_10.6.1,pci_dss_11.4,gdpr_IV_35.7.d, @@ -258,8 +258,8 @@ Wazuh ruleset .. code-block:: xml - - 20007 + + 60106 \.+ ^2$ Windows Workstation Logon Success