Convert sequence correlation rules to group rules - #2096
Conversation
Each Sequence detection is rewritten as a Group: predicates carry over, transitions fold into MatchCriteria, and ordering plus WithinTimeFrameMinutes are dropped. To keep behavior close to the old sequences, each rule's LookbackWindowMinutes now equals its former WithinTimeFrameMinutes (15-min backend floor applies), with RateMinutes scaled to keep lookback >= 1.5x rate. Three high-severity rules (S3 exfiltration, user takeover via password reset, backdoor admin role) use 1.5x lookback with 0.5x rate so any pair within the original timeframe is guaranteed to be seen by at least one query window. All renamed rules get new RuleIDs (FOLLOWED BY -> WITH/WITHOUT, or a .Group suffix); old IDs are listed in deprecated.txt and pack references are updated. Tests pass 28/28 via pat test against a live instance. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
PR SummaryMedium Risk Overview Scheduling shifts from daily Deprecation and references: prior RuleIDs are listed in Reviewed by Cursor Bugbot for commit d7fb954. Bugbot is set up for automated code reviews on this repo. Configure here. |
Description
Converts all 23 Sequence correlation rules in
correlation_rules/to Group rules with new RuleIDs.MatchCriteria; ordering andWithinTimeFrameMinutesare dropped (no Group equivalent).LookbackWindowMinutesnow equals its formerWithinTimeFrameMinutes(15-min backend floor), withRateMinutesscaled to keep lookback ≥ 1.5× rate. Three high-severity rules (S3 exfiltration+deletion, user takeover via password reset, backdoor admin role) use 1.5× lookback / 0.5× rate so any pair within the original timeframe is guaranteed to land in a query window.FOLLOWED BY→WITH/WITHOUT, otherwise a.Groupsuffix. Old IDs added todeprecated.txt; all pack and rule-description references updated.pat test --path correlation_rules/passes 28/28 against a live instance.Checklist
make fmt && make lintpasspat testagainst a live Panther instance (28/28)THREAT-734