Skip to content

Commit

Permalink
Create 600000-active_response.xml
Browse files Browse the repository at this point in the history
  • Loading branch information
taylorwalton authored Feb 22, 2024
1 parent 6c0575e commit 8307aab
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions Active_Response/600000-active_response.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
<group name="active_response,">
<rule id="600000" level="10">
<decoded_as>json</decoded_as>
<field name="active_response">windows_firewall</field>
<description>Windows Firewall Active Response triggered.</description>
<group>socfortress,</group>
<options>no_full_log</options>
</rule>
</group>

0 comments on commit 8307aab

Please sign in to comment.