Skip to content

New FalconIoaRule

bk-cs edited this page Sep 22, 2022 · 22 revisions

New-FalconIoaRule

SYNOPSIS

Create a custom Indicator of Attack rule within a rule group

DESCRIPTION

Requires 'Custom IOA Rules: Write'.

PARAMETERS

Name Type Min Max Pattern Allowed Pipeline PipelineByName Description
Name String False True Rule name
PatternSeverity String critical
high
medium
low
informational
False True Rule severity
RuletypeId String 1
2
5
6
9
10
11
12
False True Rule type
DispositionId Int32 10
20
30
False True Disposition identifier [10: Monitor, 20: Detect, 30: Block]
FieldValue Object[] False True An array of rule properties
Description String False True Rule description
Comment String False True Audit log comment
RulegroupId String ^[a-fA-F0-9]{32}$ False True Rule group identifier

SYNTAX

New-FalconIoaRule [-Name] <String> [-PatternSeverity] <String> [-RuletypeId] <String> [-DispositionId] <Int32> -FieldValue] <Object[]> [[-Description] <String>] [[-Comment] <String>] [-RulegroupId] <String> [-WhatIf] [-Confirm] <CommonParameters>]

Generated 20220922 using PSFalcon v2.2.3

Clone this wiki locally