• 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Help configuring the Corporate EDR Version
#1
[Image: edrconfig.png]

Hello community,
I’m configuring the EDR module and I see it supports rule lists (import/export). I’d like to expand the baseline rules safely without causing false positives or system instability.

Where do you recommend sourcing reliable rule ideas or detection guidance?

For example: CISA advisories, NIST recommendations, MITRE ATT&CK mappings, or other reputable public resources that can be translated into EDR rules.
Any suggestions or rule pack structures you’ve tested in real endpoints would be appreciated.
Thanks!
  Reply


Messages In This Thread
Help configuring the Corporate EDR Version - by thomasb4083 - 02-18-2026, 12:58 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)