edf28367e4
* [New] Lateral Movement Alerts from a Newly Observed Entity High-order rules to prioritize lateral movement alerts triage (detects multiple lateral movement alerts from a source.ip or user.id that was observed for the first time in the previous 5 days). * Update lateral_movement_multi_alerts_new_userid.toml * Update lateral_movement_multi_alerts_new_srcip.toml * Update lateral_movement_multi_alerts_new_userid.toml * Update lateral_movement_multi_alerts_new_userid.toml * Update lateral_movement_multi_alerts_new_userid.toml * Update rules/cross-platform/lateral_movement_multi_alerts_new_srcip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/lateral_movement_multi_alerts_new_userid.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/lateral_movement_multi_alerts_new_srcip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/lateral_movement_multi_alerts_new_userid.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/lateral_movement_multi_alerts_new_srcip.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update rules/cross-platform/lateral_movement_multi_alerts_new_userid.toml Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Apply suggestion from @Mikaayenson Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com> * Update lateral_movement_multi_alerts_new_userid.toml * Update lateral_movement_multi_alerts_new_srcip.toml * Update lateral_movement_multi_alerts_new_userid.toml * Update lateral_movement_multi_alerts_new_userid.toml --------- Co-authored-by: Mika Ayenson, PhD <Mikaayenson@users.noreply.github.com>