Skip to content

[Rule Tuning] Review Registry-based EQL Rules for Sysmon Compatibility #1766

@w0rk3r

Description

@w0rk3r

Description

Some rules that monitor registry changes are not compatible with sysmon. Some examples of tunings were:

We need to review our ruleset to ensure that we have compatible rules where intended.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions