Jul 27 2022 11:48 PM
I need to create a suppression rule for alert Suspicious "Encryption" behaviour was blocked
I enter to this alert, next choose create suppression rules.
And next I choose in IOCs part Choose IOCs
In the conditions
Entity Role: Trigger Equals I want to choose process from the select field but those process are with Process ID. For example [52862] gpg2
So generally I don't know and I have some worries if this Process ID provided in bracket is only example and doesn't have any matters and will have applied to all process gpg2 or this suppression rule will apply only to process with the exactly the same Process id.
In this alert I have three instances of gpg2 with variouss Process ID and I have possibilty to choose all of those gpg2 process from select field.