Basic Detection & Response
An introduction to the principles of detection and response with an examination of basic DR rules.
What are Detection & Response (DR) Rules for?
The Basics
Components
Events
A Basic DR Rule
Combining Rules with Boolean Operators
Logical Inversion
Lookbacks
Variables
Transforms
Resources
Stateful Rules
Namespaces & Targets
False Positive Rules
The Big Picture