elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Tuning] Suspicious Web Browser Sensitive File Access #4029

Closed Samirbous closed 1 month ago

Samirbous commented 1 month ago

related discussion https://github.com/elastic/integrations/issues/10901#issue-2490392777

the rule contains the correct index but the incorrect exclusion process.Ext.effective_parent.executable (replaced by Effective_process.executable).

protectionsmachine commented 1 month ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation

w0rk3r commented 1 month ago

Also: https://github.com/elastic/detection-rules/issues/3721