elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.91k stars 492 forks source link

[Rule Tuning] rc.local/rc.common File Creation #3805

Closed Aegrah closed 3 months ago

Aegrah commented 3 months ago

Summary

Converts the rule from new_terms to EQL by adding a robust set of exclusions. 0 hits in telemetry last 90d, 0 FPs in my stack last year.