elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 491 forks source link

[Rule Tuning] CWP Rule Review and Tuning (AWS) #1873

Closed terrancedejesus closed 2 years ago

terrancedejesus commented 2 years ago

Link to rule

AWS Integration Rules

Description

The following rules are older than 90 days and are missing investigation notes. Investigation notes will be added and each rule examined via telemetry and through simulation to determine tuning is necessary or not.

SHolzhauer commented 2 years ago

@terrancedejesus What is it you are trying to do here? I'd like to help on this one if possible.

terrancedejesus commented 2 years ago

8.3 Azure Conclusion In 8.3 we mainly reviewed did the following: