This commit is contained in:
gitj121 2021-11-05 15:10:01 -07:00
Родитель 9ffad045a3
Коммит 6dcda7ee6a
1 изменённых файлов: 2 добавлений и 2 удалений

Просмотреть файл

@ -1,7 +1,7 @@
id: e9ae5729-b4b9-4f93-9bc0-34ed379c78f0
id: 011c84d8-85f0-4370-b864-24c13455aa94
name: CoreBackUp Deletion in correlation with other related security alerts
description: |
'This query will help detect attackers attempt to delete backup containers in correlation with other alerts that could have triggered to help possibly reveal more details of attacker activity.
'This query will help detect attackers attempt to delete backup containers in correlation with other alerts that could have triggered to help possibly reveal more details of attacker activity.
Though such an activity could be legitimate as part of business operation, some ransomware actors may perform such operation to cause interruption to regular business services.'
severity: Medium
requiredDataConnectors: