heroui logo

Wiz Alert Passthrough Rule

Panther Rules

View Source
Summary
The 'Wiz Alert Passthrough Rule' is designed to enhance and provide context for security alerts generated by the Wiz platform. It plays a critical role in security monitoring by allowing security teams to assess the nature of potential threats through enriched alert details. The rule operates on alerts categorized under 'Wiz.Issues', specifically focusing on incidents that may indicate high-severity risks such as the exploitation of public-facing applications or vulnerabilities that have been actively exploited in the wild. The rule's logging capabilities ensure that alerts can be tracked and examined, aiding incident response efforts by providing relevant information about the context of the threat, including the severity and status of alerts. Parameters such as deduplication period and threshold for alerts ensure that the security team does not receive redundant notifications. The prescribed runbook advises reviewing alert details to ascertain the presence of malicious behavior and whether appropriate countermeasures have been taken. Through this methodical approach, organizations can better manage and prioritize their responses to potential threats.
Categories
  • Cloud
  • Infrastructure
  • Application
Data Sources
  • WMI
  • Logon Session
  • Web Credential
ATT&CK Techniques
  • T1190
Created: 2024-07-01