Skip to content

Commit a91576f

Browse files
committed
Merge branch 'forti-endpoint' of https://github.com/elastic/detection-rules into forti-endpoint
2 parents 9da8ed1 + 56eecac commit a91576f

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

rules/cross-platform/command_and_control_socks_fortigate_endpoint.toml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ note = """## Triage and analysis
6363
### Response and remediation
6464
6565
- Immediately isolate the affected system from the network to prevent further unauthorized access or data exfiltration.
66-
- Terminate the suspicious processes and all associated childs and parents.
66+
- Terminate the suspicious processes and all associated children and parents.
6767
- Conduct a thorough review of the system's configuration files to identify unauthorized changes.
6868
- Reset credentials for any accounts associated with the source machine.
6969
- Implement network-level controls to block traffic via SOCKS unless authorized.

0 commit comments

Comments
 (0)