Hi everyone. I am working on enabling curated detections via composite detections. One issue that I have not been able to figure out yet so far is, is there a UDM value that defines whether a curated detection rule is broad or precise? I looked at the meta fields of the curated detections and used the network inspection tool as well to look at the actual json format. So far I have not been able to find such a field.
My usecase is to write separate composite detections for precise curated detections and broad curated detections. I have a rule that consumes detections from curated detections but, as far as I know, it is not possible to distinguish whether these detections come from precise or broad rules.
Thanks in advance.




