splunk / security_content

Splunk Security Content

Home Page:https://research.splunk.com

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Experimental Detection "Remote Desktop Network Traffic" False Positives

ccl0utier opened this issue · comments

Rule Remote Desktop Network Traffic should be updated to disregard "blocked" traffic (e.g.: add ... AND All_Traffic.action = "allowed") to prevent false positives.

Merged a fix in #2403