Closed terrancedejesus closed 1 week ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Pull Request
Issue link(s):
Summary - What I changed
Not Available
in Microsoft 365 login rules for impossible activity and brute forcingHow To Test
Testing requires access to the data, however, below is a screenshot of matches from previous emulation. Note that both rules for impossible travel or rare logins are new terms and thresholds, therefore not replicable via Discover to show reduced volume.
Checklist
bug
,enhancement
,schema
,Rule: New
,Rule: Deprecation
,Rule: Tuning
,Hunt: New
, orHunt: Tuning
so guidelines can be generatedmeta:rapid-merge
label if planning to merge within 24 hoursContributor checklist