Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Rule to kill communication with malicious IPs

$
0
0

For disable networking, if it's a 64 bit machine you may want to review this:

 

Disable Networking Action not working for 64bit in LEM rule - SolarWinds Worldwide, LLC. Help and Support

 

For the process name, I'm not sure that the WebTrafficAudit event is going to have any process information relating to the browser to use in that action, especially as that event is not likely coming from the local machine but a web filter or firewall. I'm pretty sure it has user agent information, but not really the same thing. You could always see if you could filter the rule down to the user agent/browser and then just have versions of the rule appropriate for each browser exe.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>