IBM QRadar: Rules

From Wiki
Revision as of 18:48, 19 January 2025 by Ebasso (talk | contribs) (→‎Exemplos)

Uma Rule (regra) é um grupo de testes que podem desencadear uma ação se condições específicas forem atendidas.


Artigos

Exemplos

Rule Description

Apply Potential Windows Enumeration Detected
and when an event matches any of the following BB: Windows Endpoint Events
and when the event matches Event ID is any of 4688
and when the event matches Command (custom) any of [whoami or tasklist or system info]
and NOT when the source OP is on of the following IP addresses || Example

. .
. .

Ver também