Cortex Endpoint Prevention Policy Rule Created

Detects the creation of new endpoint prevention policy rules for Windows, Linux, or macOS within the Cortex management audit logs. This activity allows security administrators to monitor changes to security posture and endpoint protection configurations.