olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.13k stars 177 forks source link

large whistelists cause unexplainabe false results #21

Closed olafhartong closed 5 years ago

olafhartong commented 5 years ago

I've encountered this in the process create whitelist, where once it reached a certain limit all searches using it output massive amounts of false data.

I'm working on a fix, rebuilding the whitelist filtering somewhat. Added benefit is this shaves a bunch of the search times so performance gain!

olafhartong commented 5 years ago

The fix is applied to the repo, leaving this ticket open till after the new app has been published on Splunkbase