mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Update 600000-active_response.xml
This commit is contained in:
committed by
GitHub
parent
b8b2c759f8
commit
8763616267
@@ -6,9 +6,15 @@
|
|||||||
<group>socfortress,</group>
|
<group>socfortress,</group>
|
||||||
<options>no_full_log</options>
|
<options>no_full_log</options>
|
||||||
</rule>
|
</rule>
|
||||||
|
<rule id="600001" level="13">
|
||||||
|
<decoded_as>json</decoded_as>
|
||||||
|
<field name="copilot_action">true</field>
|
||||||
|
<description>Copilot-ACTION: Automation Event</description>
|
||||||
|
<options>no_full_log</options>
|
||||||
|
</rule>
|
||||||
</group>
|
</group>
|
||||||
<group name="sysmon_config,">
|
<group name="sysmon_config,">
|
||||||
<rule id="600001" level="3">
|
<rule id="600002" level="3">
|
||||||
<decoded_as>json</decoded_as>
|
<decoded_as>json</decoded_as>
|
||||||
<field name="group">^SysmonConfigReload$</field>
|
<field name="group">^SysmonConfigReload$</field>
|
||||||
<description>Sysmon config $(step).</description>
|
<description>Sysmon config $(step).</description>
|
||||||
|
Reference in New Issue
Block a user