Skip to content
Draft
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Another update to defaults in deployments
  • Loading branch information
pyth0n1c committed Jul 17, 2025
commit 60a4d687b2ee989a2d85dba69902e1bf0e5ed714
4 changes: 2 additions & 2 deletions deployments/escu_default_configuration_anomaly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ description: This configuration file applies to all detections of type anomaly.
These detections will use Risk Based Alerting.
scheduling:
cron_schedule: '{minute} * * * *'
earliest_time: -70m@m
latest_time: -10m@m
earliest_time: -60m@m
latest_time: +10m@m
schedule_window: auto
alert_action:
rba:
Expand Down
4 changes: 2 additions & 2 deletions deployments/escu_default_configuration_baseline.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ author: Patrick Bareiss
description: This configuration file applies to all detections of type baseline.
scheduling:
cron_schedule: '{minute} 0 * * *'
earliest_time: -1450m@m
latest_time: -10m@m
earliest_time: -1440m@m
latest_time: +10m@m
schedule_window: auto
type: Baseline
4 changes: 2 additions & 2 deletions deployments/escu_default_configuration_correlation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,8 +6,8 @@ description: This configuration file applies to all detections of type Correlati
These correlations will generate Notable Events.
scheduling:
cron_schedule: '{minute} * * * *'
earliest_time: -70m@m
latest_time: -10m@m
earliest_time: -60m@m
latest_time: +10m@m
schedule_window: auto
alert_action:
notable:
Expand Down
4 changes: 2 additions & 2 deletions deployments/escu_default_configuration_hunting.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ author: Patrick Bareiss
description: This configuration file applies to all detections of type hunting.
scheduling:
cron_schedule: '{minute} * * * *'
earliest_time: -70m@m
latest_time: -10m@m
earliest_time: -60m@m
latest_time: +10m@m
schedule_window: auto
type: Hunting
6 changes: 3 additions & 3 deletions deployments/escu_default_configuration_ttp.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,9 @@ author: Patrick Bareiss
description: This configuration file applies to all detections of type TTP.
These detections will use Risk Based Alerting and generate Notable Events.
scheduling:
cron_schedule: '{minute_range}/15 * * * *'
earliest_time: -15m@m
latest_time: now
cron_schedule: '*/15 * * * *'
earliest_time: -60m@m
latest_time: +10m@m
schedule_window: auto
alert_action:
notable:
Expand Down