Rule library
// Detection
Detection coverage reduced from the console
A detection rule was disarmed or a suppression created. Both narrow what the platform reports, and an intruder who reaches the console will reach for exactly these controls before doing anything noisier.
HighInvestigating0alerts raisedSignature
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
Any event where eventType is one of PLATFORM_RULE_DISABLED, PLATFORM_SUPPRESSION_CREATED
{
"kind": "match",
"where": [
{
"op": "in",
"field": "eventType",
"value": [
"PLATFORM_RULE_DISABLED",
"PLATFORM_SUPPRESSION_CREATED"
]
}
]
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (0)
What this rule has actually caught.
Never fired
Armed, but nothing in the retained window has matched it.
Rule
- Category
- Platform
- ATT&CK tactic
- Defense Evasion
- Technique
- T1562.001
- Kind
- Signature
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 0
- First fired
- Never
- Last fired
- Never
- Escalated to cases
- 0
- Dismissed benign
- 0