Skip to content

[Rule Tuning] Scheduled Task Activity via pwsh #3534

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Mar 26, 2024

Conversation

Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Mar 26, 2024

Summary

Fixes an issue where destination.ip in () is used. Issue is resolved by leveraging destination.address in ().

Errors:
image

Validates fine:
image

@Aegrah Aegrah merged commit 760b99b into main Mar 26, 2024
@Aegrah Aegrah deleted the rule_tuning_execution_scheduled_task_powershell branch March 26, 2024 13:45
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
protectionsmachine pushed a commit that referenced this pull request Mar 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport: auto Domain: Endpoint OS: Windows windows related rules Rule: Tuning tweaking or tuning an existing rule Team: TRADE
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants