Hello,
Since Friday evening, we have been receiving more than 400 daily alerts from a custom GTI IOC ( on domain) matching rule.
Many detections involve well-known legitimate domains such as Microsoft, Google, GitHub, DigiCert and Windows Update. Before Friday, the alert volume was normal.
We also noticed that the graph.metadata.threat field is now marked as deprecated in the YARA-L editor, but we could not find clear documentation about its replacement.
Has there been a recent change to GTI GLOBAL_CONTEXT data or entity enrichment?
What is the recommended replacement for graph.metadata.threat when matching GTI indicators in YARA-L?
Is anyone else experiencing the same issue?
Thank you.

