Adding a collection of Sigma rules

To add a collection of Sigma rules:

  1. Do one of the following:
    • for a group of protected devices, open the application policy properties window.
    • for an individual protected device, open the application settings for the device.
  2. In the Anomaly Detection using Sigma rules section, click the Add button.

    The Adding a rules collection window opens.

  3. Use the Choose a rules collection drop-down list to do one of the following:
    • Select one of the collections of Sigma rules supplied by Kaspersky.
    • Select the Custom rules collection option to add a custom collection of Sigma rules.
  4. If you are adding a custom collection of Sigma rules, enter a unique name for the collection in the corresponding field.
  5. Click OK.

In the Settings of Anomaly Detection using Sigma rules section, a line appears with the name of the created rule collection, which is enabled by default (the toggle button to the left of the collection name is in the Enabled position). When you create a custom collection of Sigma rules, it does not contain any rules at first.

See also

Adding Sigma rules to a custom collection

Page top