Title Block process by executable content pattern
ID RA3405
Description Block a process execution by its executable content pattern (i.e. specific string, keyword, binary pattern etc)
Author your name/nickname/twitter
Creation Date YYYY/MM/DD
Category Process
Stage RS0003: Containment
References
Requirements
  • DN_zeek_conn_log

Workflow

Description of the workflow for single Response Action in markdown format.
Here newlines will be saved.