Title Get ability to block process by executable content pattern
ID RA1411
Description Make sure you have the ability to block process by its executable content pattern (i.e. specific string, keyword, binary pattern etc)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Category Process
Stage RS0001: Preparation
References
Requirements
  • DN_zeek_conn_log

Workflow

Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.