Closed YamatoSecurity closed 2 months ago
@YamatoSecurity Let me confirm one thing! The aggregation condition rule also did not count Events with hits, https://github.com/Yamato-Security/hayabusa/issues/1375 but isn't this behavior particularly intended?
If either issue does not work as intended, I will fix it both!💪
@YamatoSecurity I have a question! Which of the following is the best number of numbers to output to event with hits?
@YamatoSecurity Let me confirm one thing! The aggregation condition rule also did not count Events with hits, #1375 but isn't this behavior particularly intended?
If either issue does not work as intended, I will fix it both!💪
Thanks! Yes, I think we should include the | count
rules as well.
@YamatoSecurity I have a question! Which of the following is the best number of numbers to output to event with hits?
- Number of all events matching correlation
- Number of sets of events matching correlation
What do you mean by sets of events
?
I was thinking the total number of events that any rule matched on.
So for example, if 50 failed logon events caused 50 failed logon alerts plus 1 password spray alert then it would be 50 events with hits
(not 51. We would still use 51 for total detections though). Also if the the 50 failed logon events caused just the 1 password spray alert (because the default generate: false
behavior, then still it would be 50 events with hits
. (and 1 total detection)
What do you think?
@YamatoSecurity Thank you for comment :) Yes, I think it is good! I will modify it with the above specifications!
@fukusuket Sorry I noticed this bug after merging the previous PR..
I am using this rule:
and this command:
./target/release/hayabusa csv-timeline -d ../hayabusa-sample-evtx -w -r ~/Desktop/test.yml
It gives me this summary:
Problems:
Top 5 computers with most unique detections
shows onlyn/a
but should include the correlation rule resultsEvents with hits / Total events: 0 / 26,341 (Data reduction: 26,341 events (100.00%))
should sayEvents with hits / Total events: 2 / 26,341 (Data reduction: 26,339 events (99.99%))