How a rule decides
Each rule has a condition, an attack category, a MITRE ATT&CK technique and impact scores for confidentiality, integrity and availability. Severity comes from the highest of those three scores. Rules can look back over stored logs, remove duplicate alerts and group new alerts under an existing one. Here are a few of the built-in rules.
- RDP brute force attack
- Kerberoasting attack detection
- AWS CloudTrail log suspended
- Cobalt Strike DNS beacon pattern detected
- ESXi ransomware attack detection