Closed Aegrah closed 6 months ago
In order to integrate auditd_manager seamlessly, we prepared for this issue by getting #3430 in. This PR removes the check for the event.action == "auditd_manager.auditd"
, allowing us to make the rules compatible.
In #3451 the event.action field was removed from all auditd_manager queries, and the "Data Source: Auditd Manager" tag was added.
exec
rather than fork
, maybe remove from cross-platform? The above rule tunings have been merged. This round of rule tuning is finished.
Meta Summary
Many of the new Linux rules currently do not leverage all potential indices. While doing performance analysis and tuning, my second goal is to ensure that the rules compatible with other data sources, thus (endgame, auditbeat, auditd_manager) will be added to the rule index list.
Estimated Time to Complete
3 - 5 days, depending on how much time is being spent on it. This meta will be one that can be worked at whenever some additional time is available.
Notes
This round of tuning does not only focus on FP/TP analysis, but also on:
Tasklist