Rule Health
Every approval and override, rolled up per detection rule over the last 30 days.
8 rules ended as False Positive or Whitelist more than 90% of the time and used about 114 analyst hours this month. Rule 5710 alone took 1292 minutes. Fixing the top three would give most of that time back without losing any escalation from the last 30 days.
| Rule | Engine | 30d volume | False positive | Whitelisted | Ticketed | Analyst min | Precision trend | Recommendation | |
|---|---|---|---|---|---|---|---|---|---|
5710 sshd: attempt to login using a non-existent user | Wazuh | 62 | 100% | 0% | 0% | 1292 | |||
2001219 ET SCAN Potential SSH Scan | Suricata | 58 | 12% | 88% | 0% | 1113 | |||
31151 Multiple web server 400 error codes from same source | Wazuh | 44 | 95% | 2% | 2% | 1020 | |||
5503 PAM: User login failed | Wazuh | 34 | 97% | 0% | 3% | 910 | |||
100200 custom Custom: repeated auth failures for service account | Wazuh | 37 | 0% | 95% | 5% | 802 | |||
2010935 ET SCAN Suspicious inbound to MSSQL port 1433 | Suricata | 40 | 98% | 3% | 0% | 726 | |||
2024364 ET SCAN Possible Nmap User-Agent Observed | Suricata | 31 | 100% | 0% | 0% | 583 | |||
550 Integrity checksum changed | Wazuh | 19 | 26% | 74% | 0% | 418 | |||
31103 SQL injection attempt | Wazuh | 14 | 57% | 0% | 43% | 372 | |||
5712 sshd: brute force trying to get access | Wazuh | 18 | 17% | 11% | 72% | 322 | |||
9000131 custom LOCAL MALWARE periodic outbound HTTP beacon | Suricata | 10 | 30% | 0% | 70% | 223 | |||
9000124 custom LOCAL TLS self-signed cert on internal service | Suricata | 8 | 63% | 13% | 25% | 209 | |||
2522000 ET TOR Known Tor Exit Node Traffic | Suricata | 9 | 0% | 0% | 100% | 208 | |||
60204 Multiple Windows logon failures | Wazuh | 10 | 20% | 0% | 80% | 152 | |||
9000123 custom LOCAL DNS excessively long subdomain | Suricata | 6 | 33% | 0% | 67% | 80 |
Uncaptured patterns
Activity in the raw logs that no current rule alerts on, but that resembles past escalations.
Slow SSH password guessing below rule threshold
4 to 6 failures per hour from rotating 203.0.113.0/24 addresses against cbt-bastion-01 over 3 days. Never reaches the 8 in 120 s frequency of rule 5712.
Resembles 3 past Open Ticket escalations (credential stuffing)
Service account logon to workstation segment
svc_sql authenticated interactively on 2 finance workstations (10.30.2.0/24). Service accounts never log on there in the 30 day baseline.
Resembles 1 past escalation (lateral movement)
Large outbound transfer after hours from DB host
cbt-db-03 sent 2.1 GB to 198.51.100.61 over HTTPS at 00:40. No rule covers outbound volume from database hosts.
Resembles 2 past escalations (exfiltration)