IBM QRadar: Rules: Difference between revisions
No edit summary |
|||
Line 12: | Line 12: | ||
{| class="wikitable" | {| class="wikitable" | ||
|- | |- | ||
! Rule !! Description | |||
|- | |- | ||
| | |||
Apply '''Potential Windows Enumeration Detected'''</br> | Apply '''Potential Windows Enumeration Detected'''</br> | ||
'''and''' when an event matches '''any''' of the following '''BB: Windows Endpoint Events'''</br> | '''and''' when an event matches '''any''' of the following '''BB: Windows Endpoint Events'''</br> | ||
Line 21: | Line 21: | ||
'''and NOT''' when the source OP is on of the following '''IP addresses''' || Example | '''and NOT''' when the source OP is on of the following '''IP addresses''' || Example | ||
|- | |- | ||
| . || . | |||
|- | |- | ||
| . || . | |||
|} | |} | ||
Revision as of 18:48, 19 January 2025
Uma Rule (regra) é um grupo de testes que podem desencadear uma ação se condições específicas forem atendidas.
Artigos
Exemplos
Rule | Description |
---|---|
Apply Potential Windows Enumeration Detected | |
. | . |
. | . |