Skip to content

Correlation Rules to Meaningful Alert? #1011

Answered by c3s4rfred
hackdefendr asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @hackdefendr to make the windows rules work you have to follow the windows agent integration, the windows agent will collect the logs from the machine and then you can test windows alerts like failed logins -> rule "Windows: Probable Password guessing". Note: to test, perform 5 failing attempts within 60 seconds.

Best regards

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@c3s4rfred
Comment options

@hackdefendr
Comment options

@c3s4rfred
Comment options

Answer selected by c3s4rfred
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants