elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Fix event.action conditions - AD Rules #3874

Closed w0rk3r closed 3 months ago

w0rk3r commented 3 months ago

Summary

Fix the event.action conditions.

This PR introduced hard coded values to the event.action fields for 5136 and 4662 events, which break the conditions we have on our rules.