161ea402fe
* [New Rule] Kerberos Traffic from Unusual Process * removed timeline_id * adjusted args for better perf * added potential rare FPs * Update rules/windows/credential_access_kerberoasting_unusual_process.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/credential_access_kerberoasting_unusual_process.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/credential_access_kerberoasting_unusual_process.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/credential_access_kerberoasting_unusual_process.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>