Skip to content

Commit 3f3759d

Browse files
authored
Update multiple_alerts_elastic_defend_netsecurity_by_host.toml
1 parent 4418340 commit 3f3759d

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules/cross-platform/multiple_alerts_elastic_defend_netsecurity_by_host.toml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,7 @@ This rule correlate any Elastic Defend alert with suspicious events from Network
8484
8585
### False positive analysis
8686
87+
- IP address ranges overlap where the host.ip value from the Elastic Defend alert is unrelated to the source.ip value from the Network Security alert.
8788
- Alerts from routine administrative tasks may trigger multiple alerts. Review and exclude known benign activities such as scheduled software updates or system maintenance.
8889
- Security tools running on the host might generate alerts across different tactics. Identify and exclude alerts from trusted security applications to reduce noise.
8990
- Automated scripts or batch processes can mimic adversarial behavior. Analyze and whitelist these processes if they are verified as non-threatening.

0 commit comments

Comments
 (0)