Skip to content

[Rule Tuning] Host Files System Changes via Windows Subsystem for Linux - typos #5012

@richlv

Description

@richlv

Link to Rule

https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml

Rule Tuning Type

Data Quality - Ensuring integrity and quality of data used by detection rules.

Description

This rule has some typos / redundancy in the name and description.

  • Rule name: "Files System" → "File System"
  • In the description: “Detects files creation” -> “Detects file creation”
  • In the description: “WSL for Linux” - redundant, expands to "Windows Subsystem for Linux for Linux".

Example Data

No response

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions