mirror of
https://github.com/socfortress/Wazuh-Rules.git
synced 2025-10-23 00:02:11 +00:00
8 lines
327 B
XML
8 lines
327 B
XML
<group name="threat_intel,">
|
|
<rule id="100651" level="12">
|
|
<field name="abuseipdb.abuse_confidence_score" type="pcre2" negate="yes">^0$</field>
|
|
<description>IP with $(abuseipdb.abuse_confidence_score)% confidence of abuse was connected to.</description>
|
|
<group>abuseipdb,abuseipdb_alert,</group>
|
|
</rule>
|
|
</group>
|