Rule library
// Detection

Detection coverage reduced from the console

A detection rule was disarmed or a suppression created. Both narrow what the platform reports, and an intruder who reaches the console will reach for exactly these controls before doing anything noisier.

HighInvestigating0alerts raisedSignature
Armed

What this rule does

Rendered from the stored logic, so it cannot drift from what executes.

Any event where eventType is one of PLATFORM_RULE_DISABLED, PLATFORM_SUPPRESSION_CREATED

{
  "kind": "match",
  "where": [
    {
      "op": "in",
      "field": "eventType",
      "value": [
        "PLATFORM_RULE_DISABLED",
        "PLATFORM_SUPPRESSION_CREATED"
      ]
    }
  ]
}

Revise

Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.

Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city

Alerts raised (0)

What this rule has actually caught.

Never fired

Armed, but nothing in the retained window has matched it.

Rule

Category
Platform
ATT&CK tactic
Defense Evasion
Technique
T1562.001
Kind
Signature
State
Armed
Created
7d ago
Last changed
7d ago

Firing history

Total alerts
0
First fired
Never
Last fired
Never
Escalated to cases
0
Dismissed benign
0

Related