New User - Getting Hammered by False Positives
Newbie looking for a link or general guide that will help me tweak some of these alerts. One in particular:
Rule |
Rule Name: Ransomware detected on a host |
Remediation: |
Rule Description: Identifies excessive non-executable file changes by the same process on a Windows host. Requires Windows Security logs or FortiSIEM Agent to be running on the host. |
Seems to occur anytime a user copies a folder. Help!
