Closed w0rk3r closed 2 months ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Issues
Resolves #3392
Summary - What I changed
Converts some KQL queries to EQL (in rules that don't benefit from it like
new_terms
/threshold
) to simplify rule tunings and solve case sensitiveness problems.How To Test
Copy and paste the query in the SDE cluster removing the
event.code
for the AD ones.