我在 /var/ossec/etc/rules/local_rules.xml 中有一个 powershell 规则
规则是:
<group name="sysmon,">
<rule id="255000" level="12">
<if_group>sysmon_event1</if_group>
<field name="sysmon.image">\\powershell.exe||\\.ps1||\\.ps2</field>
<description>Sysmon - Event 1: Bad exe: $(sysmon.image)</description>
<group>sysmon_event1,powershell_execution,</group>
</rule>
</group>
如您所见,rule.level 为 12。但是当我查看 alerts.json 时,我看到了这个结果。
{"timestamp":"2022-02-02T00:29:24.590-0800","rule":{"level":8,"description":"Sysmon - Event 1: Process creation Windows PowerShell","id":"61603","firedtimes":5,"mail":false,"groups":["windows","sysmon",>
rule.level 为 8。可能是什么问题,我该如何解决?