mcafee_epo rule 65501
Description
$(ThreatName)
Fires when
Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.
-
decoded_as=mcafee-epo2 -
Matches no fields of its own.
Rule dependencies
Depends on
-
composes · Wazuh if_sid
65500
Rule logic
Source file