diff --git a/rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml b/rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml index 77d551d1fd6..45a0fd3a4c6 100644 --- a/rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml +++ b/rules/integrations/endpoint/impact_elastic_ransomware_prevented.toml @@ -40,7 +40,6 @@ Generally, our ransomware protection is tuned to have extremely low false positi - Quickly identifying the compromised credentials is critical to remediate Ransomware attacks. - Verify if there are any other alert types (Behavior or Memory Threat) associated with the same host or user or process within the same time. - ### False positive analysis - Installers and backup software, which can make a large number of modifications to documents (especially during a restore operation).