elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Tuning] Suspicious .NET Reflection via PowerShell #4112

Closed Samirbous closed 1 week ago

Samirbous commented 1 week ago

Excluding common Microsoft native assemblies (Microsoft.*.dll, System.*.dll) often loaded via ::Load function.

protectionsmachine commented 1 week ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation