From d853e8d85ea328b05da250c9d8dcb041bd32d63b Mon Sep 17 00:00:00 2001 From: akozlovets098 Date: Tue, 12 Dec 2023 15:44:39 +0200 Subject: [PATCH] Add references to rules (sentinelone_rules) --- rules/sentinelone_rules/sentinelone_alert_passthrough.yml | 1 + rules/sentinelone_rules/sentinelone_threats.yml | 1 + 2 files changed, 2 insertions(+) diff --git a/rules/sentinelone_rules/sentinelone_alert_passthrough.yml b/rules/sentinelone_rules/sentinelone_alert_passthrough.yml index 935d220fe..5e16edc36 100644 --- a/rules/sentinelone_rules/sentinelone_alert_passthrough.yml +++ b/rules/sentinelone_rules/sentinelone_alert_passthrough.yml @@ -3,6 +3,7 @@ Description: SentinelOne Alert Passthrough DisplayName: "SentinelOne Alert Passthrough" Enabled: true Filename: sentinelone_alert_passthrough.py +Reference: https://www.sentinelone.com/blog/feature-spotlight-introducing-the-new-threat-center/ Severity: High Tests: - ExpectedResult: true diff --git a/rules/sentinelone_rules/sentinelone_threats.yml b/rules/sentinelone_rules/sentinelone_threats.yml index b22c72f3c..f861b3cf8 100644 --- a/rules/sentinelone_rules/sentinelone_threats.yml +++ b/rules/sentinelone_rules/sentinelone_threats.yml @@ -3,6 +3,7 @@ Description: 'Passthrough SentinelOne Threats ' DisplayName: "SentinelOne Threats" Enabled: true Filename: sentinelone_threats.py +Reference: https://www.sentinelone.com/blog/feature-spotlight-introducing-the-new-threat-center/ Severity: High Tests: - ExpectedResult: true