Creating an IOA rule based on event search conditions
To create an IOA rule based on event search conditions:
Select the Threat Hunting section in the program web interface window.
The event search form opens.
Perform an event search using design mode or source code mode.
Click the Save as IOA rule button.
The Save window opens.
In the New IOA rule name field, enter the name of the IOA rule.
Click the Save button.
The event search condition will be saved. The new IOA rule with the specified name is displayed in the IOC/IOA Analysis section, IOA Analysis subsection.