Open w0rk3r opened 1 month ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Issues
Summary
Adjusts to rules to introduce or improve compatibility and documentation with 3rd party (and, in this case, our Endgame) data such as Sysmon, MDE, and S1.
EDR field compatibility matrix: https://docs.google.com/spreadsheets/d/1ZaRmSXIVYLO9AGXeZge3u0W938aGxbfd6Vha52Rs1_I/edit?usp=sharing
Blocker
To use SentinelOne cloud funnel data right now, we would need to min_stack the rules to 8.13, so we are going to hold off on merging these until 8.16 is released and support for 8.12 is dropped. The updated_date is set to the 8.16 public release date.