Skip to content

Commit

Permalink
Update sigmahq-title-convention.md
Browse files Browse the repository at this point in the history
  • Loading branch information
nasbench committed Aug 6, 2024
1 parent 2ed4f1d commit f501bfa
Showing 1 changed file with 12 additions and 4 deletions.
16 changes: 12 additions & 4 deletions sigmahq/sigmahq-title-convention.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,25 +69,33 @@ Example:
- "Renamed xxx Execution"
- "UAC Bypass Using ..."
Rules of level `informational` or `low` are not intended to be used to create alerts on their own. Their purpose is to conserve events or criteria of relevance, to be used in correlations or for ideas for threat hunting. A rule of those levels will by definition not create false positives as they should not be used for alerting.
#### Informational / Low Level Rules
Events matching rules of level `informational` or `low` are not intended to be used to create alerts on their own. Their purpose is to conserve events or criteria of relevance, to be used in correlations or for ideas for threat hunting. A rule of those levels will by definition not create false positives as they should not be used for alerting.

The title should therefore be general and should not indicate that the rule describes suspicious or malicious behavior.

Example : `Net.exe Execution`

`medium` rules can have environment dependent false positives and require a tuning/evaluation phase before deploying to production environments.
#### Medium Level Rules

Events matching `medium` level rules rules can have environment dependent false positives and require a tuning/evaluation phase before deploying to production environments.

Keywords used to indicate this:

- "Potential "

`high` rules requires a prompt review.
#### High Level Rules

Events matching `high` level rules requires a prompt review.

Keywords used to indicate this:

- "Suspicious "

`critical` rules should be reviewed immediately
#### Critical Level Rules

Events matching `critical` level rules should be reviewed immediately
The title must therefore be precise and indicate the specific threat.

Keywords used to indicate this:
Expand Down

0 comments on commit f501bfa

Please sign in to comment.