Correlation Tuning Simulator

Adjust correlation rule parameters and see their impact on alert volume and detection coverage

Rule Parameters

5
5 min
Medium

Daily Alert Volume

Detection Coverage Over Time

Alerts/Day

0

Generated alerts

Coverage

0%

Threats detected

Noise Ratio

0%

False positives

Efficiency

0

Coverage/Alert

Tuning Tips: Lower thresholds increase detection but generate more alerts. Wider time windows catch slow attacks but may create noise. Balance coverage against analyst capacity (target: 20-50 alerts/day for a single analyst).