Open w0rk3r opened 1 week ago
These guidelines serve as a reminder set of considerations when tuning an existing rule.
updated_date
matches the date of tuning PR merged.min_stack_version
should support the widest stack versions.name
and description
should be descriptive and not include typos.query
should be inclusive, not overly exclusive. Review to ensure the original intent of the rule is maintained.
Summary
Excludes activity where the target IP is one of the IPs of the host, including localhost. Adds
data_stream.namespace
to theby
condition to fix FPs one of our users reported in Slack where IPs match between namespaces (unrelated envs).