π Fix DGA alert name override placeholder
This commit is contained in:
Π ΠΎΠ΄ΠΈΡΠ΅Π»Ρ
a507a0b8c1
ΠΠΎΠΌΠΌΠΈΡ
9a37033814
|
@ -104,12 +104,12 @@ entityMappings:
|
|||
- identifier: Url
|
||||
columnName: Url
|
||||
alertDetailsOverride:
|
||||
alertDisplayNameFormat: Potential communication from {{SrcIpAddr} with a Domain Generation Algorithm (DGA) based host {{Name}}
|
||||
alertDisplayNameFormat: Potential communication from {{SrcIpAddr}} with a Domain Generation Algorithm (DGA) based host {{Name}}
|
||||
alertDescriptionFormat: A client with address {{SrcIpAddr}} communicated with host {{Name}} that have a domain name that might have been generated by a Domain Generation Algorithm (DGA), identified by the pattern {{DGADomain}}. DGAs are used by malware to generate rendezvous points that are difficult to predict in advance. This detection uses the top 1 million domain names to build a model of what normal domains look like and uses the model to identify domains that may have been randomly generated by an algorithm.
|
||||
customDetails:
|
||||
DGAPattern: DGADomain
|
||||
NameCount: NameCount
|
||||
version: 1.1.4
|
||||
version: 1.1.5
|
||||
kind: Scheduled
|
||||
metadata:
|
||||
source:
|
||||
|
|
ΠΠ°Π³ΡΡΠ·ΠΊΠ°β¦
Π‘ΡΡΠ»ΠΊΠ° Π² Π½ΠΎΠ²ΠΎΠΉ Π·Π°Π΄Π°ΡΠ΅