mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 08:12:16 +00:00
Create 100651-abuseipdb.xml
This commit is contained in:
7
AbuseIPDB/100651-abuseipdb.xml
Normal file
7
AbuseIPDB/100651-abuseipdb.xml
Normal file
@@ -0,0 +1,7 @@
|
||||
<group name="threat_intel,">
|
||||
<rule id="100651" level="12">
|
||||
<field name="abuseipdb.abuse_confidence_score" type="pcre2" negate="yes">^0$</field>
|
||||
<description>IP with $(abuseipdb.abuse_confidence_score)% confidence of abuse was connected to.</description>
|
||||
<group>abuseipdb,abuseipdb_alert,</group>
|
||||
</rule>
|
||||
</group>
|
Reference in New Issue
Block a user