Tune EXPERIMENTAL rules found noisy in 12h alert review - #711
Merged
bryant-smith merged 1 commit intoSep 2, 2026
Merged
Conversation
sid:9870000 (NTLM V1 anon logon): track by_dst -> by_src, suppress window 1hr -> 1day. by_dst let a single sweeping host bypass suppression entirely (one greif host swept 251 destinations in one continuous episode, generating 253 alerts instead of 1). sid:9870007 (Kerberoasting RC4 request, silent flag-setter) + sid:5017969 (RC4 Kerberoasting -> AD CS correlation): xbits:noalert is a no-op in the legacy engine (confirmed: every other noalert rule in this ruleset uses flexbits:noalert and has 0 hits over 7 days; 9870007 was the only xbits:noalert rule and leaked 13 alerts in 12h). Converted both the setter and its isset counterpart to flexbits so the correlation keeps working while the rule goes properly silent.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
sid:9870000(NTLM V1 anon logon):track by_dst->by_src, suppress window 1hr -> 1day.by_dstlet a single sweeping host bypass suppression entirely — one greif host swept 251 destinations in one continuous ~3.4hr episode, generating 253 alerts instead of 1.sid:9870007(Kerberoasting RC4 request, silent flag-setter) +sid:5017969(RC4 Kerberoasting -> AD CS correlation, production):xbits:noalertis a no-op in the legacy engine — confirmed every othernoalertrule in this ruleset usesflexbits:noalertand has 0 hits over 7 days, while 9870007 was the onlyxbits:noalertrule and leaked 13 alerts in 12h. Converted both the setter and itsissetcounterpart toflexbitsso the correlation keeps working while the rule goes properly silent.Test plan
🤖 Generated with Claude Code
https://claude.ai/code/session_01QFitvKrjdjusS7gosybzNT