Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC1-LAB-011Medium
Browser LabLD-SOC1-LAB-011Medium20 min

Tune a Noisy Detection Without Going Blind

A password-spray detection is firing so often that analysts have started ignoring it — and a real spray may be hiding in the noise. Here is the rule and the three sources it fired on this hour, with context. Your job is detection work, not just triage: find the true positive, find the benign cause of the noise, choose the tuning that silences the noise without losing the attack, confirm the tuned rule still fires on the spray, and map it to ATT&CK.

What you will be able to do

  • Separate a true positive from false positives in a rule's alerts
  • Choose a narrow tuning that preserves detection
  • Validate the tuned rule against the real attack
Detection EngineeringSIEM OperationIncident TriageT1110.003Brute Force: Password Spraying

Sign in to start this lab.

Sign in