Importing a user-defined TAA (IOA) rule

You can import an IOC format file and use it to scan events and create Targeted Attack Analyzer alerts.

It is highly recommended to test custom TAA (IOA) rules in a test environment before you import them. Custom TAA (IOA) rules may cause performance issues, in case of which stable performance of Kaspersky Anti Targeted Attack Platform is not guaranteed

To import a TAA (IOA) rule:

  1. In the window of the program web interface, select the User rules section, TAA subsection.

    This opens the TAA (IOA) rule table.

  2. Click Import.

    This opens the file selection window on your local computer.

  3. Select the file that you want to upload and click Open.

    This opens the New TAA (IOA) rule window.

  4. Select or clear the State check box if you want to change the usage status of the rule when scanning the events database.
  5. On the Details tab, in the Name field, enter the name of the rule.
  6. In the Description field, enter any additional information about the rule.
  7. In the Importance drop-down list, select the importance level to be assigned to alerts generated using this TAA (IOA) rule.
    • Low.
    • Medium.
    • High.
  8. In the Confidence drop-down list, select the level of confidence of this rule based on your estimate:
    • Low.
    • Medium.
    • High.
  9. Under Apply to, select check boxes corresponding to servers on which you want to apply the rule.
  10. On the Query tab, verify the defined search conditions. Make changes if necessary.
  11. Click Save.

The user-defined TAA (IOA) rule is imported into the program.

You can also add a TAA (IOA) rule by saving events database search conditions in the Threat Hunting section.

See also

Viewing the TAA (IOA) rule table

Viewing the information of a user-defined TAA (IOA) rule

Searching for alerts and events in which TAA (IOA) rules were triggered

Filtering and searching TAA (IOA) rules

Resetting the TAA (IOA) rule filter

Creating a user-defined TAA (IOA) rule based on event search conditions

Enabling and disabling TAA (IOA) rules

Modifying a user-defined TAA (IOA) rule

Deleting user-defined TAA (IOA) rules

Page top