-
Notifications
You must be signed in to change notification settings - Fork 598
Open
Labels
Rule: Tuningtweaking or tuning an existing ruletweaking or tuning an existing ruleTeam: TRADEcommunity
Description
Link to Rule
Rule Tuning Type
False Positives - Reducing benign events mistakenly identified as threats.
Description
I may be missing something but it looks like this alert can FP because of the dns.question.name exclusions and the fact that the field won't appear in the connection records after the domain is resolved. Is there a reason not to limit the network portion to DNS lookups?
Example Data
msiexec process create -> msiexec queries acroipm2.adobe.com -> msiexec connects to the resolved IP
It looks like the DNS query is essentially being ignored because the rule only needs the process and the connection to X.X.X.X
Metadata
Metadata
Assignees
Labels
Rule: Tuningtweaking or tuning an existing ruletweaking or tuning an existing ruleTeam: TRADEcommunity