Detection Tuner

Investigate noisy/common alerts and create false positive (FP) rules to suppress benign detections. Analyzes detection frequency over 7 days, identifies patterns, generates and tests FP rules with operator approval before deployment. Use for tuning detection noise, reducing alert fatigue, suppressing known-safe activity, or when specific detections need filtering. Human-in-the-loop workflow ensures no FP rules are deployed without explicit approval.

refractionpoint 56c4df0 14.4 KB Updated

File contents

refractionpoint/lc-ai/tree/main/marketplace/plugins/lc-essentials/skills/detection-tuner commit 56c4df0c59

Frequently asked questions

npx skillmds@latest add refractionpoint/detection-tuner