# Normalizing usernames in executable paths to reduce "rare" detection noise?

**URL:** <https://discuss.elastic.co/t/normalizing-usernames-in-executable-paths-to-reduce-rare-detection-noise/271281>\
**Category:** Elastic Security\
**Tags:** elastic-stack-machine-learning\
**Created:** [April 26, 2021, 4:15pm UTC](https://discuss.elastic.co/t/normalizing-usernames-in-executable-paths-to-reduce-rare-detection-noise/271281 "2021-04-26T16:15:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hukel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hukel/32/78624_2.png) [@hukel](https://discuss.elastic.co/u/hukel)\
**Post date:** [April 26, 2021, 4:15pm UTC](https://discuss.elastic.co/t/normalizing-usernames-in-executable-paths-to-reduce-rare-detection-noise/271281/1 "2021-04-26T16:15:45Z")

</div>

Is anyone "normalizing" executable or command line paths in the **process** schema?

We see some noise in our **rare** detections for processes that run under the user's home drive.

Considering changing "fred", "mary", "bob", and "alice" here:

```auto
"executable": "\\Users\\fred\\AppData\\Local\\Google\\Chrome\\User Data\\SwReporter\\89.259.200\\software_reporter_tool.exe",

```

to this, so that the ML job won't see each different user's instance of the same tool as an anomaly.

```auto
"executable": "\\Users\\##USERNAME##\\AppData\\Local\\Google\\Chrome\\User Data\\SwReporter\\89.259.200\\software_reporter_tool.exe",

```

---

<div class="post-metadata">

**Author:** ![bfilar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bfilar/32/87801_2.png) [@bfilar](https://discuss.elastic.co/u/bfilar)\
**Post date:** [April 27, 2021, 5:00pm UTC](https://discuss.elastic.co/t/normalizing-usernames-in-executable-paths-to-reduce-rare-detection-noise/271281/2 "2021-04-27T17:00:40Z")

</div>

So the Security Data Science team is exploring different ways to normalize process paths and command lines in event data. One effort that may be of interest is within the ProblemChild (Anomalous Parent-Child Process Events) Classifier set to be released in 7.13.

You can see the painless script for normalization here: [examples/normalize\_ppath.json at master · elastic/examples · GitHub](https://github.com/elastic/examples/blob/master/Machine%20Learning/ProblemChild/normalize_ppath.json)

If you have other ideas or edge cases, pass them along!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2021, 5:01pm UTC](https://discuss.elastic.co/t/normalizing-usernames-in-executable-paths-to-reduce-rare-detection-noise/271281/3 "2021-05-25T17:01:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
