chainguard-dev / malcontent

detect malicious program behaviors
Apache License 2.0
407 stars 26 forks source link

Measure if "threat_hunting" ruleset is worth the CPU cost #451

Open tstromberg opened 2 weeks ago

tstromberg commented 2 weeks ago

We always downgrade these rules to "medium" - how much CPU time do we waste on them?

I'd argue that if the rules add 3s+ to a bincapz run on a large binary, I'd remove them.