8ae6c4fd23
* [New] Correlated Alerts on Similar User Identities This rule correlates alerts from multiple integrations and event categories that involve different user.name values which may represent the same real-world identity. It uses an LLM-based similarity analysis to evaluate whether multiple user identifiers (e.g. naming variations, formats, aliases, or domain differences) likely belong to the same person. * Update multiple_alerts_llm_by_user_entity.toml * Update multiple_alerts_llm_by_user_entity.toml * Update multiple_alerts_llm_by_user_entity.toml * Update multiple_alerts_llm_by_user_entity.toml * Update rules/cross-platform/multiple_alerts_llm_by_user_entity.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update multiple_alerts_llm_by_user_entity.toml * Apply suggestion from @terrancedejesus Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> * Update multiple_alerts_llm_by_user_entity.toml --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>