elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] 3rd Party EDR Compatibility - 7 #4031

Open w0rk3r opened 1 month ago

w0rk3r commented 1 month ago

Issues

Summary

Adjusts to rules to introduce or improve compatibility and documentation with 3rd party data such as Sysmon, MDE, and S1.

EDR field compatibility matrix: https://docs.google.com/spreadsheets/d/1ZaRmSXIVYLO9AGXeZge3u0W938aGxbfd6Vha52Rs1_I/edit?usp=sharing

Blocker

To use SentinelOne cloud funnel data right now, we would need to min_stack the rules to 8.13, so we are going to hold off on merging these until 8.16 is released and support for 8.12 is dropped. The updated_date is set to the 8.16 public release date.

protectionsmachine commented 1 month ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation