You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
False Negatives - Enhancing detection of true threats that were previously missed.
Description
We need to investigate the behavior of this rule when winlog.event_data.Properties is marked as ignored due to the length of the field. When a field is marked as ignored, you cannot query it using either KQL or EQL, but we should validate the behavior on ES|QL.
Example Data
No response
The text was updated successfully, but these errors were encountered:
Link to Rule
https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_high_number_ad_properties.toml
Rule Tuning Type
False Negatives - Enhancing detection of true threats that were previously missed.
Description
We need to investigate the behavior of this rule when
winlog.event_data.Properties
is marked as ignored due to the length of the field. When a field is marked as ignored, you cannot query it using either KQL or EQL, but we should validate the behavior on ES|QL.Example Data
No response
The text was updated successfully, but these errors were encountered: