Skip to main content
Version: 2.1.1-preview

ORCA.242 - Important protection alerts responsible for AIR activities are enabled.

Overview​

Automated Incident Response (AIR) triggers off certain alerts that fire in the environment. AIR is responsible for detecting further anomalies and providing automated remediation actions designed to mitigate threats/attacks. It is important that these alerts are enabled so that AIR can function correctly.

Remediation action​

Enable important protection alerts that are responsible for AIR activities.

Test Metadata​

FieldValue
Test IDORCA.242
SeverityHigh
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA242
TagsEXO, ORCA, ORCA.242

Source​

  • Pester test: tests/orca/Test-ORCA242.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA242.ps1