Skip to content

Commit 56eecac

Browse files
SamirbousCopilot
andauthored
Update rules/cross-platform/command_and_control_socks_fortigate_endpoint.toml
Co-authored-by: Copilot <[email protected]>
1 parent f9dd283 commit 56eecac

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/command_and_control_socks_fortigate_endpoint.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ note = """## Triage and analysis
6363
### Response and remediation
6464
6565
- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration.
66-
- Terminate the suspicious processes and all associated childs and parents.
66+
- Terminate the suspicious processes and all associated children and parents.
6767
- Conduct a thorough review of the system's configuration files to identify unauthorized changes.
6868
- Reset credentials for any accounts associated with the source machine.
6969
- Implement network-level controls to block traffic via SOCKS unless authorized.

0 commit comments

Comments
 (0)