You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
False Negatives - Enhancing detection of true threats that were previously missed.
Description
I'm not sure if these were left out for a reason, but it would make sense to me to group any deletion of backups via wbadmin into one alert. Is it worth including 'delete backup' and 'delete systemstatebackup' or should they make separate alerts?
Example Data
edit: Screenshots don't show it but backup and systemstatebackup prompt for -keepVersions, -version or -deleteOldest, but I don't think these should matter for detection.
The text was updated successfully, but these errors were encountered:
Link to Rule
https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_deleting_backup_catalogs_with_wbadmin.toml
Rule Tuning Type
False Negatives - Enhancing detection of true threats that were previously missed.
Description
I'm not sure if these were left out for a reason, but it would make sense to me to group any deletion of backups via wbadmin into one alert. Is it worth including 'delete backup' and 'delete systemstatebackup' or should they make separate alerts?
Example Data
edit: Screenshots don't show it but backup and systemstatebackup prompt for -keepVersions, -version or -deleteOldest, but I don't think these should matter for detection.
The text was updated successfully, but these errors were encountered: