Skip to content

Review Linux and macOS rules for Endgame compatibility #2369

Open
@Mikaayenson

Description

@Mikaayenson

Description

Review rules for Endgame compatibility and add index.

  • Create an endgame stack for testing purposes.
  • Check datasets and make sure our rule query aligns.
  • Check the fields in the query to make sure the field is available in the endgame event.
  • Document differences between the Endgame dataset and Endpoint dataset if any appear.

cc @DefSecSentinel @Samirbous @w0rk3r @shashank-elastic

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions