Hi Team,
I require assistance with fine-tuning the rule: ["recon activity detected from internal host"] to minimize false positives and optimize its performance. Your support in this matter would be greatly appreciated.
PFA.
Hi Team,
I require assistance with fine-tuning the rule: ["recon activity detected from internal host"] to minimize false positives and optimize its performance. Your support in this matter would be greatly appreciated.
PFA.
Best answer by jstoner
For community members to provide additional guidance, some additional specifics may be required to help understand the kind of challenges you are trying to overcome. This tuning is likely to be specific to your organization to minimize what you define as false positives.
Since you are looking for internal to internal, i'd probably start by making sure that I've defined the internal ranges of my network and start by having something like below as it pertains to both principal and target.
(net.ip_in_range_cidr($e.principal.ip, "10.0.0.0/8") or net.ip_in_range_cidr($e.principal.ip, "172.16.0.0/12") or net.ip_in_range_cidr($e.principal.ip, "192.168.0.0/16"))
For simplicity it may also be wise to separate the ping sweep from the port scan. Also the thresholds in the conditions do not align to the description.
Are there specific IPs that are more interesting than others to focus the sweep on, ie stuff below 1024? specific ports that indicate ldap, http/s, sql, etc activity?
Additional context is important to factor into this and perhaps adjusting the match window from 50 minutes downward or the conditions upward might be something else to consider.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.