Hi,
3 weeks ago i posted a question about the alarm in subject. Now that i set all the correlation rules and alarms, seems work fine. Now i encountering another problem. I get a lot of false positive alarms. I am trying to tune the correlation rules but i cant find a way. I was thinking to increase the number of the events needed for the alarm to trigger, but it can be a no-function workaround. I want that the context is both R2L and L2L. Any suggestion?
The rule is: 7 events from the same source with the same destination towards the RDP port within 10 minutes.
I already set a filter for events subtype is "pass", but still get a lot of false positives.
Can anyone help me?
Thank you in advance