elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Ignore "Not Available" in `o365.audit.UserId` for Microsoft 365 Rules #4105

Closed terrancedejesus closed 1 week ago

terrancedejesus commented 1 week ago

Pull Request

Issue link(s):

Summary - What I changed

How To Test

Testing requires access to the data, however, below is a screenshot of matches from previous emulation. Note that both rules for impossible travel or rare logins are new terms and thresholds, therefore not replicable via Discover to show reduced volume.

Screenshot 2024-09-25 at 6 22 12 PM

Checklist

Contributor checklist

protectionsmachine commented 1 week ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation