2d5d826be7
* [New] Multiple External EDR Alerts by Host This rule uses alert data to determine when multiple external EDR alerts involving the same host are triggered. Analysts can use this to prioritize triage and response, as these hosts are more likely to be compromised. * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml * Update multiple_external_edr_alerts_by_host.toml