flâneur — a map of the web's best reading

Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Medium

medium.com · 5,302 words · saved by 1 readers

Chronicle SIEM’s Detection Engine enables you to run correlation rules that can generate detections or alerts, but without careful planning, you can easily be overwhelmed with YARA-L alerts. In this post I cover approaches I use when deploying, evaluating, and tuning YARA-L rules, to avoid such a scenario. I will be using the excellent Chronicle Community Rules repository as a practical example to illustrate the planning, deployment and tuning phase. github.com To quote from John Stoner’s excellent blog, the Chronicle Community rules are intended to: For this post, I’m using the Chronicle Community rules. While many offer precise, high-fidelity detections, others are templates designed to demonstrate Chronicle SIEM’s capabilities, which provide an excellent learning aide for how to tune rules. ⚠️ Exercise caution with any template type rule; direct deployment into production without evaluation and tuning can lead to an overwhelming number of alerts. While the core concepts of rule tuni

Tuning YARA-L Rules in Chronicle SIEM Chris Martin (@thatsiemguy) 21 min read · Feb 5, 2024 -- 1 Listen Share Chronicle SIEM’s Detection Engine enables you to run correlation rules that can generate detections or alerts, but without careful planning, you can easily be overwhelmed with YARA-L alerts. In this post I cover approaches I use when deploying, evaluating, and tuning YARA-L rules, to avoid such a scenario. How I look when tuning noisy rules I will be using the excellent Chronicle Community Rules repository as a practical example to illustrate the planning, deployment and tuning phase.

Explore this link on the map →

saved by

related reading