Skip to content

Commit

Permalink
Update 200850-crowdstrike.xml
Browse files Browse the repository at this point in the history
  • Loading branch information
taylorwalton authored Aug 29, 2022
1 parent 52a4ec1 commit 26236db
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions Crowdstrike/200850-crowdstrike.xml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
<group name="crowdstrike,siemconnector">
<rule id="200850" level="5">
<field name="metadata.customerIDString">\.+</field>
<options>no_full_log</options>
<description>CrowdStrike Alert - $(event.OperationName)</description>
</rule>
<rule id="200851" level="1">
Expand All @@ -16,6 +17,7 @@
<rule id="200853" level="8">
<if_sid>200850</if_sid>
<field name="event.Severity">\.+</field>
<options>no_full_log</options>
<description>CrowdStrike Alert - $(event.DetectDescription)</description>
</rule>
</group>

0 comments on commit 26236db

Please sign in to comment.