Using Playbook #12088
Using Playbook
#12088
Replies: 1 comment
-
We recommend against enabling all Critical, High, and Medium items. In particular, one of the High severity plays (
First, you need to know your environment. Then, you should only enable those plays which are relevant to your environment AND which would be critical enough for you to engage the incident response process. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I am new to security onion. Just got it setup on my network. So in playbook, it seems like all the items are set to draft to start. How do you decide which ones to change to active? I went it and did all Critical, High, and medium items and am getting overloaded with alerts.
Beta Was this translation helpful? Give feedback.
All reactions