Skip to content

Convert sequence correlation rules to group rules - #2096

Merged
arielkr256 merged 3 commits into
developfrom
cr-sequence-to-group
Jun 17, 2026
Merged

arielkr256 merged 3 commits into
developfrom
cr-sequence-to-group

Conversation

@arielkr256

@arielkr256 arielkr256 commented Jun 12, 2026 •

Copy link
Copy Markdown
Contributor

Description

Converts all 23 Sequence correlation rules in correlation_rules/ to Group rules with new RuleIDs.

  • Predicates carry over as-is; transitions fold into MatchCriteria; ordering and WithinTimeFrameMinutes are dropped (no Group equivalent).
  • To stay close to sequence behavior, each rule's LookbackWindowMinutes now equals its former WithinTimeFrameMinutes (15-min backend floor), with RateMinutes scaled to keep lookback ≥ 1.5× rate. Three high-severity rules (S3 exfiltration+deletion, user takeover via password reset, backdoor admin role) use 1.5× lookback / 0.5× rate so any pair within the original timeframe is guaranteed to land in a query window.
  • New RuleIDs: FOLLOWED BY → WITH/WITHOUT, otherwise a .Group suffix. Old IDs added to deprecated.txt; all pack and rule-description references updated.
  • Tests updated where sequence-only semantics no longer apply (timeframe negatives, absence-event ordering). pat test --path correlation_rules/ passes 28/28 against a live instance.

Checklist

  • make fmt && make lint pass
  • pat test against a live Panther instance (28/28)

THREAT-734

Each Sequence detection is rewritten as a Group: predicates carry over,
transitions fold into MatchCriteria, and ordering plus
WithinTimeFrameMinutes are dropped.

To keep behavior close to the old sequences, each rule's
LookbackWindowMinutes now equals its former WithinTimeFrameMinutes
(15-min backend floor applies), with RateMinutes scaled to keep
lookback >= 1.5x rate. Three high-severity rules (S3 exfiltration, user
takeover via password reset, backdoor admin role) use 1.5x lookback with
0.5x rate so any pair within the original timeframe is guaranteed to be
seen by at least one query window.

All renamed rules get new RuleIDs (FOLLOWED BY -> WITH/WITHOUT, or a
.Group suffix); old IDs are listed in deprecated.txt and pack references
are updated. Tests pass 28/28 via pat test against a live instance.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@arielkr256
arielkr256 requested review from a team as code owners June 12, 2026 15:37
@cursor

cursor Bot commented Jun 12, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Wide change to high-severity multi-event detections (AWS, Okta, Snowflake, etc.); group rules no longer enforce strict event order, so alert timing and false-positive/negative behavior may differ from sequence rules despite tuned lookback/rate.

Overview
Migrates 23 correlation_rules/ detections from Sequence to Group correlation: Transitions and per-edge WithinTimeFrameMinutes are replaced by shared MatchCriteria on the same fields, and RuleIDs are renamed (FOLLOWED BY → WITH/WITHOUT, or a .Group suffix).

Scheduling shifts from daily RateMinutes: 1440 to tighter intervals aligned with each rule’s former transition window; LookbackWindowMinutes is shortened to those windows (with rate/lookback ratios chosen so pairs that used to fit in the old timeframe still overlap a run). Predicate groups, MinMatchCount, and Absence behavior are preserved where applicable.

Deprecation and references: prior RuleIDs are listed in deprecated.txt; packs, indexes, detection-coverage.json, and a few rule descriptions (e.g. OpenAI/Snowflake correlation name references) point at the new IDs. Correlation tests are adjusted for group semantics (e.g. Okta/Push ordering, secret quarantine timestamps). .gitignore adds .mcp.json.

Reviewed by Cursor Bugbot for commit d7fb954. Bugbot is set up for automated code reviews on this repo. Configure here.

@arielkr256 arielkr256 added the correlation_rules Correlation rules establish correlations across logs, identify anomalies, and model complex attack b label Jun 12, 2026
@arielkr256
arielkr256 enabled auto-merge June 17, 2026 15:33
@arielkr256
arielkr256 added this pull request to the merge queue Jun 17, 2026
Merged via the queue into develop with commit 47a62cb Jun 17, 2026
16 checks passed
@arielkr256
arielkr256 deleted the cr-sequence-to-group branch June 17, 2026 15:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

correlation_rules Correlation rules establish correlations across logs, identify anomalies, and model complex attack b

3 participants