Title Get ability to block process by executable metadata
ID RA1408
Description Make sure you have the ability to block process by its executable metadata (i.e. signature, permissions, MAC times)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Category Process
Stage RS0001: Preparation
References
Requirements
  • DN_zeek_conn_log

Workflow

Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.