Correlation Directives

One of the main tools for generating alarms, and contains one or more of the Correlation Rules. After all the conditions specified in a Correlation Rule have been matched, the system guarantees a Directive Event and advances to the next Correlation Level. Directives may be built-in, custom, or user contributed.
Topic revision: r2 - 20 Nov 2020, SheriffCyberSecurity
Copyright 2020 Sheriff Cyber Security, LLC. All rights reserved.