Closed w0rk3r closed 2 months ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Summary
Converts the rule to the new_terms rule type, uses query DSL to exclude noisy patterns, and to include the
system32
&syswow64
folders.The rule is very noisy and the majority of the hits are FPs, so this aims to reduce the volume and improve the FP x TP rate.