Elastic Security: יצירת Detection Rule ו-Investigation Guide

Detection Rule טובה ב-Elastic Security מתחילה מהתנהגות שצריך לזהות ומהנתונים הזמינים, לא מבחירת שפה אקראית. בוחרים Rule type מתאים, מאמתים ECS ושדות, כותבים Query, מגדירים Schedule ו-Lookback, Risk ו-Severity, Suppression ו-Exceptions, ומצרפים Investigation Guide שמוביל את האנליסט דרך Triage, Analysis ו-Response.
Elastic Security כוללת Detection engine שמריץ Rules על נתוני Elasticsearch ומייצר Alerts כאשר התנאים מתקיימים. היא תומכת בכמה סוגי Rules, ובהם Custom query, Event correlation באמצעות EQL, Threshold, Indicator match, New terms, ES|QL ו-Machine learning. כל סוג פותר שאלה אחרת.
Rule שמחזירה Results אינה בהכרח Detection שימושית. כדי להפוך Query למוצר תפעולי צריך Data contract, Schedule, Triage context, Risk, Exceptions, Owner, תהליך בדיקה ו-Investigation Guide. האנליסט שקיבל Alert צריך להבין תוך דקות מה זוהה, אילו שדות חשובים, מהו False Positive סביר ומה לחפש בהמשך.




