-
Notifications
You must be signed in to change notification settings - Fork 456
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Tuning] Linux BBR Tuning - Part 1 #3469
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Noisy?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
++, this rule was not capturing what I hoped it would capture. It captured way too much, too much noise, no way to tune to decent levels ATM.
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Removed changes from: - rules_building_block/collection_linux_suspicious_clipboard_activity.toml (selectively cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Removed changes from: - rules_building_block/collection_linux_suspicious_clipboard_activity.toml (selectively cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> Removed changes from: - rules_building_block/collection_linux_suspicious_clipboard_activity.toml (selectively cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
* [Tuning] Linux BBR Tuning - Part 1 * [Tuning] Linux BBR Tuning - Part 1 * Update defense_evasion_processes_with_trailing_spaces.toml * Update defense_evasion_processes_with_trailing_spaces.toml * One more tuning * Update collection_linux_suspicious_clipboard_activity.toml --------- Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com> (cherry picked from commit 3fd0358)
Summary
Part 1 of the Linux BBR DR tuning. Besides regular rule tuning, this PR added compatibility with additional data sources where possible, added correct tags/indices, fixed formatting, and checked for potential rule performance increases.