You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
False Positives - Reducing benign events mistakenly identified as threats.
Description
Seeking an upstream rule modification to skip alerting about 1Password in the "Startup or Run Key Registry Modification" rule.
Looking at the existing rule query, fields that could be used for 1Password. Presumably this would not be limited to a single hardcoded version.
Link to Rule
https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_run_key_and_startup_broad.toml
Rule Tuning Type
False Positives - Reducing benign events mistakenly identified as threats.
Description
Seeking an upstream rule modification to skip alerting about 1Password in the "Startup or Run Key Registry Modification" rule.
Looking at the existing rule query, fields that could be used for 1Password. Presumably this would not be limited to a single hardcoded version.
Example Data
No response
The text was updated successfully, but these errors were encountered: