Skip to content

Commit 4ab955a

Browse files
committed
Updates from review
1 parent af54014 commit 4ab955a

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

docs/cse/match-lists-suppressed-lists/standard-match-lists.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -548,7 +548,7 @@ The following Cloud SIEM rules refer to this match list:
548548

549549
**Target column:** Username (`Username`)
550550

551-
**Description:** Unrecognized Docker container images that may indicate an attempt to bypass security controls on existing images or escalate privileges.
551+
**Description:** Known approved Docker images that act as a whitelist. If an image is identified that is not on this list, further investigation is warranted. If approved images are identified they should be added to this list.
552552

553553
The following Cloud SIEM rules refer to this match list:
554554
* Unrecognized Container Image
@@ -621,9 +621,9 @@ The following Cloud SIEM rules refer to this match list:
621621

622622
### OneLogin_Untrusted_Location
623623

624-
**Target column:** Username (`Username`)
624+
**Target column:** IP Address (`Ip`)
625625

626-
**Description:** Users that are known to be involved with specific administrative or privileged activity.
626+
**Description:** Locations that are known to be untrusted.
627627

628628
The following Cloud SIEM rules refer to this match list:
629629
* OneLogin - API Credentials - Key Used from Untrusted Location

0 commit comments

Comments
 (0)