elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] 3rd Party EDR Compatibility - 2 #4019

Open w0rk3r opened 1 month ago

w0rk3r commented 1 month ago

Issues

Summary

Adjusts to rules to introduce or improve compatibility and documentation with 3rd party (and, in this case, our Endgame) data such as Sysmon, MDE, and S1.

EDR field compatibility matrix: https://docs.google.com/spreadsheets/d/1ZaRmSXIVYLO9AGXeZge3u0W938aGxbfd6Vha52Rs1_I/edit?usp=sharing

Blocker

To use SentinelOne cloud funnel data right now, we would need to min_stack the rules to 8.13, so we are going to hold off on merging these until 8.16 is released and support for 8.12 is dropped. The updated_date is set to the 8.16 public release date.

protectionsmachine commented 1 month ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation