The L1-Data Security Monitoring - Data Loss Prevention (DLP) - Indicators and Warnings package provides resources that allow the SOC analyst to track DLP exfiltration and policy modification events and receive an early warning when a significant DLP event occurs. User Stories supported by this package include:
• DLP Incident from a Watched User
• Confidential File transferred on a suspicious network port
• Removable Device Tracking
• Continuos DLP Incidents from the same User
• DLP Statistics
The L1-Data Security Monitoring - Data Loss Prevention - Indicators and Warningspackage falls under the Activate License
Rules tagged with MITRE ATT&CK
Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox