Add Playbook

This commit is contained in:
weslambert
2023-08-21 11:24:07 -04:00
committed by GitHub
parent 9e18fe64cf
commit 563a495725

View File

@@ -1586,6 +1586,15 @@ soc:
- rule.uuid - rule.uuid
- rule.category - rule.category
- rule.rev - rule.rev
':playbook:':
- soc_timestamp
- rule.name
- event.severity_label
- event_data.event.module
- event_data.event.category
- event_data.process.executable
- event_data.process.pid
- event_data.winlog.computer_name
queryBaseFilter: tags:alert queryBaseFilter: tags:alert
queryToggleFilters: queryToggleFilters:
- name: acknowledged - name: acknowledged