Skip to main content
Version: 2.1.0

ORCA.242 - Important protection alerts responsible for AIR activities are enabled.

Overview

Automated Incident Response (AIR) triggers off certain alerts that fire in the environment. AIR is responsible for detecting further anomalies and providing automated remediation actions designed to mitigate threats/attacks. It is important that these alerts are enabled so that AIR can function correctly.

Remediation action

Enable important protection alerts that are responsible for AIR activities.

Test Metadata

FieldValue
Test IDORCA.242
SeverityHigh
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA242
TagsEXO, ORCA, ORCA.242

Source

  • Pester test: tests/orca/Test-ORCA242.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA242.ps1