A security analyst is tuning a SIEM rule that triggers on any process creation event involving 'rundll32.exe'. The rule generates many false positives from legitimate software updates. Which tuning action would most effectively reduce false positives while maintaining detection of malicious use?
By implementing a baseline of authorized parent-child process relationships or whitelisting known-good command-line arguments, analysts can significantly suppress benign positive alerts. This targeted tuning preserves the SIEM's ability to detect anomalous or unauthorized executions of the binary while minimizing alert fatigue.
Why this answer
Creating an exception list for known legitimate processes or command lines that use rundll32.exe reduces false positives. However, the best approach is to modify the rule to include specific conditions such as parent process or command-line arguments that indicate malicious activity.