elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Include winlogbeat index in sysmon-related rules #3966

Closed w0rk3r closed 2 months ago

w0rk3r commented 2 months ago

Issue

Part of https://github.com/elastic/detection-rules/issues/3939

Summary

Adds the winlogbeat index to sysmon-related rules (that were missing the index) to cover environments that use winlogbeat to ship sysmon logs.

protectionsmachine commented 2 months ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation