disable correlation rules by default - #2114
Conversation
PR SummaryMedium Risk Overview Alongside that, detection scheduling is aligned: Index/coverage updates drop entries for AWS Privilege Escalation Via User Compromise and AWS User Takeover Via Password Reset from Reviewed by Cursor Bugbot for commit b6bde3f. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit b6bde3f. Configure here.
| RateMinutes: 1440 | ||
| TimeoutMinutes: 5 | ||
| LookbackWindowMinutes: 30 | ||
| LookbackWindowMinutes: 1800 |
There was a problem hiding this comment.
Lookback below schedule ratio minimum
Medium Severity
This change sets LookbackWindowMinutes to 1800 with RateMinutes 1440, but project guidance requires lookback at least 1.5× the run interval (2160 minutes here). That ratio avoids gaps between daily runs. The same edit also replaces attack-specific windows (e.g. OpenAI’s documented 30-minute brute-force span) with 30 hours, so re-enabling would correlate unrelated events.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit b6bde3f. Configure here.


Correlation rules should only be enabled if the underlying data sources are available.