Titre | Obtenir la possibilité de bloquer le processus par le contenu de l’exécutable |
---|---|
ID | RA1411 |
Description | Make sure you have the ability to block process by its executable content pattern (i.e. specific string, keyword, binary pattern etc) |
Auteur | your name/nickname/twitter |
Creation Date | DD.MM.YYYY |
Catégorie | Process |
Étapes | RS0001: Préparation |
References | <ul><li>https://example.com</li></ul> |
Requirements | <ul><li>DN_zeek_conn_log</li></ul> |
Workflow
Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.