Update 600000-active_response.xml

This commit is contained in:
taylor_socfortress
2025-09-22 09:54:04 -05:00
committed by GitHub
parent b8b2c759f8
commit 8763616267

View File

@@ -6,9 +6,15 @@
<group>socfortress,</group>
<options>no_full_log</options>
</rule>
<rule id="600001" level="13">
<decoded_as>json</decoded_as>
<field name="copilot_action">true</field>
<description>Copilot-ACTION: Automation Event</description>
<options>no_full_log</options>
</rule>
</group>
<group name="sysmon_config,">
<rule id="600001" level="3">
<rule id="600002" level="3">
<decoded_as>json</decoded_as>
<field name="group">^SysmonConfigReload$</field>
<description>Sysmon config $(step).</description>