contentctl
contentctl copied to clipboard
2x New CICD Checks for Detection Validation
1. summaries_only macro missing from tstats search
- this will help when folks accidentally submit a tstats based detection which directly references summariesonly=t
- spent far too long to admit troubleshooting why my latest detection didn't trigger, grr.
- also good for standardisation where this is missing
2. risk object not found in SPL
- helps ensure the risk objects are relevant
- may need to look at the last line of SPL, table/ stats or required fields, catches to ensure whole field is compared so src doesn't match on src_ip