Promote 24 zero-alert experimental rules to production sids - #710
Merged
Conversation
…ules-to-legacy Port 3 BEC-relevant Sagan Cloud rules to legacy (skip BAV2ROPC)
sid:5017961 -- gates on program:MicrosoftTeams (set from the O365 Management API .Workload field via the msapi json-input map), mirroring the existing msapi-azuread/exchange/onedrive/sharepoint dynamic entries. Lets dynamic_load-mode deployments load the Teams file-exfiltration rules (5017959/5017960) on demand instead of only via the static rules.yaml include. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pm9eFi7kuG3hhfQrWVRta3
Renumbered 24 EXPERIMENTAL rules across windows-security, msapi-azuread, sonicwall, fortinet(-aetas), and juniper(-aetas) from staging sids (9870xxx/995xx) to sequential production sids (5017962-5017985) and stripped the [EXPERIMENTAL] tag from their msg fields, per the established promotion pattern (7065f19). These 24 had zero alerts in the last 30 days per an OpenSearch alerts-index comparison against the live ruleset. Bumped .last_used_sid accordingly. Note: sid:5017982 (Juniper - Standard Web Port, formerly 9870015) stays commented out -- it was already disabled prior to this change, which is why it had zero alerts. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YBacyjARiT72fNq9sqG3ay
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
[EXPERIMENTAL]-tagged rules against 30-day alert volume in the OpenSearch alerts index; 24 of 42 EXPERIMENTAL rules across windows-security, msapi-azuread, sonicwall, fortinet(-aetas), and juniper(-aetas) had zero hits.[EXPERIMENTAL]frommsg, renumbered from staging sids (9870xxx/995xx) to sequential production sids5017962-5017985, per the established promotion pattern (7065f19)..last_used_sidaccordingly.sid:5017982(Juniper - Standard Web Port, formerly 9870015) stays commented out — it was already disabled prior to this change, which is why it had zero alerts.Test plan
[EXPERIMENTAL]tag on any of the 24 promoted ruleshttps://claude.ai/code/session_01YBacyjARiT72fNq9sqG3ay