Raksa

Rule Health

Every approval and override, rolled up per detection rule over the last 30 days.

8 rules ended as False Positive or Whitelist more than 90% of the time and used about 114 analyst hours this month. Rule 5710 alone took 1292 minutes. Fixing the top three would give most of that time back without losing any escalation from the last 30 days.

RuleEngine30d volumeFalse positiveWhitelistedTicketedAnalyst minPrecision trendRecommendation
5710
sshd: attempt to login using a non-existent user
Wazuh62100%0%0%1292
2001219
ET SCAN Potential SSH Scan
Suricata5812%88%0%1113
31151
Multiple web server 400 error codes from same source
Wazuh4495%2%2%1020
5503
PAM: User login failed
Wazuh3497%0%3%910
100200 custom
Custom: repeated auth failures for service account
Wazuh370%95%5%802
2010935
ET SCAN Suspicious inbound to MSSQL port 1433
Suricata4098%3%0%726
2024364
ET SCAN Possible Nmap User-Agent Observed
Suricata31100%0%0%583
550
Integrity checksum changed
Wazuh1926%74%0%418
31103
SQL injection attempt
Wazuh1457%0%43%372
5712
sshd: brute force trying to get access
Wazuh1817%11%72%322
9000131 custom
LOCAL MALWARE periodic outbound HTTP beacon
Suricata1030%0%70%223
9000124 custom
LOCAL TLS self-signed cert on internal service
Suricata863%13%25%209
2522000
ET TOR Known Tor Exit Node Traffic
Suricata90%0%100%208
60204
Multiple Windows logon failures
Wazuh1020%0%80%152
9000123 custom
LOCAL DNS excessively long subdomain
Suricata633%0%67%80

Uncaptured patterns

Activity in the raw logs that no current rule alerts on, but that resembles past escalations.

UP-07412 events

Slow SSH password guessing below rule threshold

4 to 6 failures per hour from rotating 203.0.113.0/24 addresses against cbt-bastion-01 over 3 days. Never reaches the 8 in 120 s frequency of rule 5712.

Resembles 3 past Open Ticket escalations (credential stuffing)

UP-116 events

Service account logon to workstation segment

svc_sql authenticated interactively on 2 finance workstations (10.30.2.0/24). Service accounts never log on there in the 30 day baseline.

Resembles 1 past escalation (lateral movement)

UP-141 events

Large outbound transfer after hours from DB host

cbt-db-03 sent 2.1 GB to 198.51.100.61 over HTTPS at 00:40. No rule covers outbound volume from database hosts.

Resembles 2 past escalations (exfiltration)