elastic / detection-rules

https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Other
1.92k stars 492 forks source link

[Rule Tuning] Active Directory Forced Authentication from Linux Host - SMB Named Pipes #4117

Open w0rk3r opened 1 week ago

w0rk3r commented 1 week ago

Summary

Excludes activity where the target IP is one of the IPs of the host, including localhost. Adds data_stream.namespace to the by condition to fix FPs one of our users reported in Slack where IPs match between namespaces (unrelated envs).

protectionsmachine commented 1 week ago

Rule: Tuning - Guidelines

These guidelines serve as a reminder set of considerations when tuning an existing rule.

Documentation and Context

Rule Metadata Checks

Testing and Validation