elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Updated setup guide #3885

Closed Aegrah closed 2 months ago

Aegrah commented 2 months ago

Summary

Added setup guide instructions to this rule, to allow customers to more easily set up the necessary auditd rules.

protectionsmachine commented 2 months ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation

approksiu commented 2 months ago

@Aegrah could you please follow the setup guide template mentioned in this issue: https://github.com/elastic/ia-trade-team/issues/410

Aegrah commented 2 months ago

@approksiu copy pasted it from the template now.