Skip to content

[Meta] MacOS Detection Rules Dilemma #4456

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
3 tasks done
DefSecSentinel opened this issue Feb 11, 2025 · 2 comments
Open
3 tasks done

[Meta] MacOS Detection Rules Dilemma #4456

DefSecSentinel opened this issue Feb 11, 2025 · 2 comments

Comments

@DefSecSentinel
Copy link
Contributor

DefSecSentinel commented Feb 11, 2025

Epic Link

https://github.com/elastic/ia-trade-team/issues/273

Meta Summary

I need to figure out what to do with MacOS detection rules. Right now I see no delineating factor for detection rule creation vs endpoint rules. One could say detection rules could be rules that are more broad in scope meant to be tuned by users but if we are leading with SIEM and our detection rules are many clients first impression of us then putting out a bunch of noisy rules that require manual tuning for client environments in order to be safe and effective doesn't sound like a winning strategy. So I need to either find a clear goal for detection rules or duplicate Endpoint Rules to Detection Rules. This Meta will be used to explore this dilemma and put into action a plan that will ensure our detection rules for macOS are useful, meaningful and actionable going forward.

Estimated Time to Complete

TBD

Potential Blockers

None at the moment

Tasking

Meta Tasks

Preview Give feedback

Potential References

No response

@DefSecSentinel
Copy link
Contributor Author

Update March 14

Review of MacOS Detection Rules is complete. I am going through now and tuning each rule (which has not been done in some time). After I create the tuning PR I will move to evaluate which Endpoint Rule I want to move over to Detection Rules and start that PR.

@DefSecSentinel
Copy link
Contributor Author

Update March 24

MacOS Detection Rule have been tuned (#4546) and a single rule deprecated (#4547).

Moving on to evaluate Endpoint rules for conversion to Detection rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant