You are responsible for identifying suspicious activity and security events across your organization's environment. You find that certain detection rules are triggering for internal IP addresses in the 192.0.2.0/8 subnet, causing false-positive alerts. You want to improve these detection rules. What should you add to the YARA-L detection rules?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion