To view information about a TAA (IOA) rule:
This opens the TAA (IOA) rule table.
This opens a window containing information about the rule.
The window contains the following information:
EventType=Process started AND FileName CONTAINS <name of the rule you are working on>
. You can edit the event search query.IDs cannot be modified. You can copy the ID by clicking the Copy value to clipboard button.
The Details tab shows the following information:
The Query tab displays the source code of the query being checked. Click the Run query link in the upper part of the window to go to the Threat Hunting section and run an event search query.