Adapter Detection & Response Rules
  • 21 Oct 2023
  • 1 Minute to read
  • Contributors
  • Dark
    Light
  This documentation version is deprecated, please click here for the latest version.

Adapter Detection & Response Rules

  • Dark
    Light

Article summary

Similar to EDR telemetry, data received via Adapters are observable via Detection & Response rules. D&R rules that action on Adapter-based data are written the same way, with event and operator qualifiers and response actions based on successful detections.

Depending on the type of adapter, you can reference adapter data directly via the platform sensor selector (e.g. aws, msdefender, crowdstrike, etc.)


Was this article helpful?

What's Next