Readding with changes
This commit is contained in:
Родитель
9ffad045a3
Коммит
6dcda7ee6a
|
@ -1,7 +1,7 @@
|
|||
id: e9ae5729-b4b9-4f93-9bc0-34ed379c78f0
|
||||
id: 011c84d8-85f0-4370-b864-24c13455aa94
|
||||
name: CoreBackUp Deletion in correlation with other related security alerts
|
||||
description: |
|
||||
'This query will help detect attackers attempt to delete backup containers in correlation with other alerts that could have triggered to help possibly reveal more details of attacker activity.
|
||||
'This query will help detect attackers attempt to delete backup containers in correlation with other alerts that could have triggered to help possibly reveal more details of attacker activity.
|
||||
Though such an activity could be legitimate as part of business operation, some ransomware actors may perform such operation to cause interruption to regular business services.'
|
||||
severity: Medium
|
||||
requiredDataConnectors:
|
||||
|
|
Загрузка…
Ссылка в новой задаче