Delinea Privilege Manager detected a bad-rated application action event

This rule is part of a beta feature. To learn more, contact Support.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Goal

Detects bad-rated application action events.

Strategy

This rule monitors the Delinea Privilege Manager logs to detect bad-rated application action events.

Triage and Response

  1. Analyze the bad-rated application action event on the computer: {{@ComputerName}}.
  2. Determine whether the flagged application {{@FileName}} located at {{@FilePath}} was executed or installed on other systems.
  3. Temporarily isolate the affected system to prevent potential spread or harm.
  4. Update the application control policy to block the flagged application.
  5. Notify the user to avoid similar activities and ensure compliance with application usage policies.