Added
Changed
- osquery: Rename alerts fields reference. (#196)
- update_ruleset is not available in worker nodes. (#225)
- Update composite rules to match only same_source_ip events. (#161)
Fixed
- Fixed active response decoder in order to match with different dates. (#223)
Removed
- Removed deprecated rules for Syscheck.