elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] min_stack New Rules that use the S1 Integration #4079

Closed w0rk3r closed 3 weeks ago

w0rk3r commented 3 weeks ago

Summary

Updates these rules with a min_stack condition to 8.13 to avoid double bumps in the version lock.

protectionsmachine commented 3 weeks ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation