Files
sigma-rules/rules/cross-platform
Samirbous d358641c45 [New] Multiple Rare Elastic Defend Behavior Rules by Host (#5738)
* [New] Multiple Rare Elastic Defend Behavior Rules by Host

Identifies hosts that triggered multiple distinct Elastic Defend behavior rules, while reducing false positives by
considering only behavior rules that appear on a single host globally (via INLINE STATS). Hosts with two or more
such rare behavior rules are more likely to be compromised and warrant prioritized triage.

* Update multiple_elastic_defend_behavior_rules_same_host_prevalence.toml

* Update multiple_elastic_defend_behavior_rules_same_host_prevalence.toml

* Update multiple_elastic_defend_behavior_rules_same_host_prevalence.toml

* Update multiple_elastic_defend_behavior_rules_same_host_prevalence.toml

* Update multiple_elastic_defend_behavior_rules_same_host_prevalence.toml

---------

Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>
2026-02-20 09:40:42 +00:00
..