Skip to content

feat: Add WEL alerts for Bridge and Enterprise machines with multi-ma…#2

Merged
jmorascalyr merged 1 commit intoalerts_fixfrom
alert_fix_the_third
Feb 21, 2026
Merged

feat: Add WEL alerts for Bridge and Enterprise machines with multi-ma…#2
jmorascalyr merged 1 commit intoalerts_fixfrom
alert_fix_the_third

Conversation

@jmorascalyr
Copy link
Owner

…chine asset correlation

  • Added 4 new WEL alert mappings: hidden scheduled tasks (bridge/enterprise), brute force success (enterprise), and AD admin group creation (enterprise)
  • Implemented target_machine field in alert mappings to specify which machine (email/bridge/enterprise) each alert correlates to
  • Updated alert resource UID logic to use separate XDR asset IDs for bridge (xdr_asset_id_bridge) and enterprise (xdr_asset_

…chine asset correlation

- Added 4 new WEL alert mappings: hidden scheduled tasks (bridge/enterprise), brute force success (enterprise), and AD admin group creation (enterprise)
- Implemented target_machine field in alert mappings to specify which machine (email/bridge/enterprise) each alert correlates to
- Updated alert resource UID logic to use separate XDR asset IDs for bridge (xdr_asset_id_bridge) and enterprise (xdr_asset_
@jmorascalyr jmorascalyr merged commit 20e3a5d into alerts_fix Feb 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant