Skip to content

[Rule Tuning] Potential Ransomware Behavior - High count of Readme files by System #4653

Open
@w0rk3r

Description

@w0rk3r

Link to Rule

https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_high_freq_file_renames_by_kernel.toml

Rule Tuning Type

Performance - Optimizing resource consumption and execution time of detection rules.

Description

Investigate ways to enhance performance in this rule, maybe using ESQL new text functions.

Context:

Example Data

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions