fd1260c109
* adjusted query to include event action and network direction filters * adjusted rule name and file name * toml linted and tags updated Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com>