A threat hunter notices an EDR rule for PowerShell encoded commands fires dozens of times per day from deployment scripts. The rule catches real attacks but also floods triage with benign automation. Which action best preserves hunting value while maintaining coverage?
Select an answer to reveal the explanation.
Short Explanation
Think of a detection rule like a smoke detector: too sensitive and you silence it; too dumb and you miss real fires. You keep hunting value by adding context and exclusions so benign automation stops drowning the signal. Don't just crank coverage or mute the alarm.
Full Explanation
Detection tuning balances recall with precision. In threat hunting, a noisy command-line detection may have high recall but low precision if it ignores known deployment paths, signed publishers, command-line arguments, parent process, and scheduled task context. Analysts add contextual exclusions and allow-lists so benign automation is suppressed while suspicious variants remain visible. This improves analyst efficiency and keeps hunting aligned with ATT&CK T1059.001 without deleting the control. Turning the rule off removes the detection path entirely, leaving a coverage gap for malicious execution. Adding more command-line rules increases alert volume and duplicates logic, worsening triage burden rather than improving signal quality. Sending every alert to manual SIEM review preserves raw detection volume but does not reduce false positives or make hunting more efficient; it only shifts the workload. Exam caveat: CompTIA expects tuning to preserve coverage, not eliminate noisy controls. Operational check: review top alert sources for seven days, correlate benign parent processes and script hashes, then implement a narrow exclusion and measure alert reduction.