-
Notifications
You must be signed in to change notification settings - Fork 570
[Rule tuning] existing hpining and strace activity rule. #2028
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why would these need to be converted to EQL rules?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
++, if we are not using sequences here, the type conversion is not needed
@brokensound77 / @w0rk3r We were under the impression EQL had performance benefits over KQL and that we would want to unify our rules but if that's not the case then I guess we will leave them and just tune as is. |
Yea, in this case, there is no benefit, so I think we are ok to close. |
@brokensound77 --> The PR contains MITRE details addition along with query changes, we can revert the query alone and keep the PR open to judge the other aspects.! |
I will be reverting query changes alone! |
@brokensound77 / @w0rk3r the query changes are reverted please review the other tuning details. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good!
Changes were requested for an older version of PR. Those changes were already reverted in this PR
* Update description and MITTRE Attack details (cherry picked from commit 2ee23bd)
* Update description and MITTRE Attack details (cherry picked from commit 2ee23bd)
* Update description and MITTRE Attack details (cherry picked from commit 2ee23bd)
* Update description and MITTRE Attack details (cherry picked from commit 2ee23bd)
* Update description and MITTRE Attack details (cherry picked from commit 2ee23bd)
Issues
#2027
Summary
-- This won't be done as it was rejected in review for having no impact.
Contributor checklist