Enabling and disabling TAA (IOA) rules

Users with the Senior security officer role can enable or disable one or several rules, as well as all rules at once.

To enable or disable the use of a TAA (IOA) rule when scanning events:

  1. In the window of the program web interface, select the User rules section, TAA subsection.

    This opens the TAA (IOA) rule table.

  2. In the row with the relevant rule, select or clear the check box in the State column.

The use of the rule when scanning events is enabled or disabled.

To enable or disable the use of all or multiple TAA (IOA) rules when scanning events:

  1. In the window of the program web interface, select the User rules section, TAA subsection.

    This opens the TAA (IOA) rule table.

  2. Select the check boxes on the left of the rules whose use you want to enable or disable.

    You can select all rules by selecting the check box in the row containing the headers of columns.

    A control panel appears in the lower part of the window.

  3. Click Enable or Disable to enable or disable all rules.

The use of the selected rules when scanning events is enabled or disabled.

In distributed solution and multitenancy mode, you can manage only global YARA rules on the PCN server. You can manage local YARA rules on SCN servers of companies to which you have access. If you want to use a local YARA rule to scan files and objects on the PCN server, you must upload a file containing this rule to the server.

Users with the Security auditor and Security officer roles cannot enable or disable YARA rules.

See also

Creating a user-defined TAA (IOA) rule based on event search conditions

Importing a user-defined TAA (IOA) rule

Viewing the TAA (IOA) rule table

Viewing custom TAA (IOA) rule details

Searching for alerts and events in which TAA (IOA) rules were triggered

Filtering and searching TAA (IOA) rules

Resetting the TAA (IOA) rule filter

Modifying a user-defined TAA (IOA) rule

Deleting user-defined TAA (IOA) rules

Page top