elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.85k stars 462 forks source link

[Rule Tuning] Improve Compatibility in WIndows BBR Detection Rules #3841

Closed w0rk3r closed 2 days ago

w0rk3r commented 5 days ago

Issues

Resolves https://github.com/elastic/detection-rules/issues/3661

Summary

Adds compatibility (where possible) to Security Logs, Sysmon, and Endgame in Windows BBRs.