Adding an IOA rule
To add an IOA rule:
- In the program web interface window, select the IOC/IOA Analysis section, IOA Analysis subsection.
The table of IOA rules opens.
- Click the Upload button.
The file selection window opens on your local computer.
- Select the file that you want to upload and click the Open button.
The New IOA rule window opens.
Click the Events link to view a list of threats in the events database matching the criteria defined in the file.
- Select or clear the State check box to apply the rule when scanning the events database.
- In the Name field, enter the name of the rule.
- In the Description field, enter any additional information about the rule.
- In the Importance drop-down list, select the importance level to be assigned to alerts generated using this IOA rule.
- In the Confidence drop-down list, select the level of confidence of this rule based on your estimate:
- Under Apply to, select check boxes corresponding to servers on which you want to apply the rule.
- On the Query tab, verify the defined search conditions. Make changes if necessary.
- Click the Save button.
The IOА rule is added.
You can also add an IOA rule by saving events database search conditions in the Threat Hunting section.
Page top