Open
Description
Rather than printing them from the rule loaded within unit tests (since the global constant is set), all output should be aggregated and raised as an actual warning to control the output.
example:
Unusual Print Spooler Child Process
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Unusual Service Host Child Process - Childless Service
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Privileges Elevation via Parent Process PID Spoofing
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.3.0 to 8.6.0 if using new features in this latest version.
Process Created with an Elevated Token
There is a new integration endpoint version 8.6.1 available! Update the rule min_stack version from 8.4.0 to 8.6.0 if using new features in this latest version.