Discussion about this post

User's avatar
Neural Foundry's avatar

Great consolidated overview of the recent detection rule changes. The Elastic updates around reducing false positives with container tool exclusions is something I've been dealing with in our enviorment where legitmate Ansible and Docker operations kept triggering persistence alerts. The new correlation rules for lateral movement detection across hosts look promising because right now tracking attack paths manually across different EDR alerts is tedious and error-prone.

No posts

Ready for more?