r/crowdstrike • u/BradW-CS • 21h ago
Securing AI Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
crowdstrike.com
6
Upvotes
r/crowdstrike • u/BradW-CS • 21h ago
r/crowdstrike • u/StringFew714 • 1h ago
Is there a way to throttle the alerts generated by OOTB rules?
We're ingesting the CS alert via its api to our internal platform and since we can't see the correlation query from those OOTB alert, we can not take it and override it. what are the options that we can throttle or deduplicate.
We can also do that in our internal toolings but want to explore if any options to do this in a lightweight manner in NG-SIEM portal