Use Case 11
Details
Create a “Sequenced Incident” for your device only
Click “Policies” in the left pane of the management console and select “Sequence rules” in the top center of the screen. Click “Create new rule.”
Type “jsmith – Sequence detection rule” in the “Name” box and click “Next”
Select the following stages and click “Create”a. Collection [TA0009]b. Exfiltration [TA0010]
Click the edit pencil in the “Include” box
Select “Specific entities (by label)” and choose your label created in use case 1
Click the edit pencil in the “Mandatory stages” box
Select “Exfiltration [TA0010]” and click “Save”
Click “Operation mode” and click “Enabled” then click “Publish rule”