Disconnected
SOCaaSRule Optimization
Go to MDRNew Support Request
SC

Rule Optimization

Loading rule data...
Total Rules Tracked

7

Noisy Rules (>40% FP)

6

Auto-Disabled

2

Recommendations Pending

7

Noisy Rules

Rule IDRule NameFP 7dFP 30dFP 90dTriggersRecommendation
R-1042Excessive Failed Logins72%68%55%3,420Tune
R-1087Suspicious PowerShell Download64%58%51%1,890Tune
R-1123Outbound DNS to Rare TLD89%85%78%5,210Disable
R-1156Service Account Interactive Login45%48%42%980Exclude
R-1201Large File Upload to Cloud Storage58%52%47%2,100Tune
R-1245Registry Run Key Modification91%88%82%7,800Disable
R-1289Network Scan Detected35%40%38%650Exclude

Auto-Tune Controls

Sigma Transpiler

Target SIEMs:

Transpiled output will appear here

Auto-Tune Audit Log

TimestampModeRules ReviewedRules Disabled
Feb 28, 2026, 02:32 PMlive483
Feb 25, 2026, 09:15 AMdry-run485
Feb 20, 2026, 11:00 AMlive452
Feb 15, 2026, 04:45 PMdry-run454