Skip to content

RA1408: Get Ability To Block Process By Executable Metadata

Summary

ID RA1408
Brief Description Make sure you have the ability to block process by its executable metadata (i.e. signature, permissions, MAC times)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Requirements
  • DN_zeek_conn_log
References
Response Stage Preparation

Description

Description of the extended_description for single Response Action in markdown format. Here newlines will be saved.