Hello everyone
I am having some difficulties with the SECOPS detection rules.
I need to make an exception in the following cases:
-If the account is in the Data Table and the action occurs during business hours, no alert should be generated.
-If the account is not in the Data Table, generate an alarm.
-If the account is not in the Data Table and outside business hours, increase the severity.
I tried to draft some conditions, but the values are incorrect.