Files
sigma-rules/rules/cross-platform
Samirbous 8ae6c4fd23 [New] Correlated Alerts on Similar User Identities (#5726)
* [New] Correlated Alerts on Similar User Identities

This rule correlates alerts from multiple integrations and event categories that involve different user.name values which
may represent the same real-world identity. It uses an LLM-based similarity analysis to evaluate whether multiple user identifiers
(e.g. naming variations, formats, aliases, or domain differences) likely belong to the same person.

* Update multiple_alerts_llm_by_user_entity.toml

* Update multiple_alerts_llm_by_user_entity.toml

* Update multiple_alerts_llm_by_user_entity.toml

* Update multiple_alerts_llm_by_user_entity.toml

* Update rules/cross-platform/multiple_alerts_llm_by_user_entity.toml

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>

* Update multiple_alerts_llm_by_user_entity.toml

* Apply suggestion from @terrancedejesus

Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>

* Update multiple_alerts_llm_by_user_entity.toml

---------

Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
2026-02-20 15:57:34 +00:00
..