- Bronze, 100 points or more
I am tuning some Unconfirmed False Positives (UFP). We have a fair number of the 'Windows SMB Enum Share DoS' events in the UFP list. They don't appear to be too frequent but there are some. I am thinking I'd like to have a rule that says "if there are less than 'x' occurences to a particular dest IP within 'y' minutes, ignore this" but it doesn't look like this can be done.
Any ideas? TIA