a1e40de4a5
* [New] Alerts From Multiple Integrations by Entity IP Higher-Order Rules that trigger on different integrations with different event.category (e.g. authentication with endpoint, email with network etc.) for the same entity (user, IP) in an interval of 4 hours. rule is set to run every 1h. - Alerts From Multiple Integrations by Source Address - Alerts From Multiple Integrations by Destination IP - Alerts From Multiple Integrations by User Name * ++ * ++ * ++ * ++ * Update rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_srcip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_srcip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update multiple_alerts_from_different_modules_by_dstip.toml * Update multiple_alerts_from_different_modules_by_dstip.toml * Update multiple_alerts_from_different_modules_by_srcip.toml * Update multiple_alerts_from_different_modules_by_user.toml * Update multiple_alerts_from_different_modules_by_dstip.toml * Update multiple_alerts_from_different_modules_by_srcip.toml * Update rules/cross-platform/multiple_alerts_from_different_modules_by_dstip.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_srcip.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update rules/cross-platform/multiple_alerts_from_different_modules_by_user.toml Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com> * Update multiple_alerts_from_different_modules_by_dstip.toml * Update multiple_alerts_from_different_modules_by_srcip.toml * Update multiple_alerts_from_different_modules_by_user.toml --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> Co-authored-by: Jonhnathan <26856693+w0rk3r@users.noreply.github.com>