Changing exclusions to Adaptive Anomaly Control rules
December 19, 2024
ID 231584
You can add, modify, and delete exclusions to Adaptive Anomaly Control rules.
Adding exclusions
You can add exclusions in either of the following ways:
- When processing Adaptive Anomaly Control detections.
- When configuring Adaptive Anomaly Control, as described later in this section.
To add an exclusion to an Adaptive Anomaly Control rule:
- Proceed to the Adaptive Anomaly Control settings page.
- Select the check box next to required rule.
- Click the Edit button.
The Exclusions from rule <rule name> window opens.
- Click the Add button.
The Add an exclusion window opens.
- Define the exclusion settings:
- Source process and Source object
The object that performed the detected actions (for example, a file that the user opened).
- Target process and Target object
The object on which the detected actions were performed (for example, a browser that uses a library that is loaded into the computer memory as a result of opening the file).
- Source process and Source object
- Click OK to close the Add an exclusion window.
The added record appears in the list of exclusions in the Exclusions from rule <rule name> window.
Modifying exclusions
To modify an exclusion to an Adaptive Anomaly Control rule:
- Proceed to the Adaptive Anomaly Control settings page.
- Select the check box next to required rule.
- Click the Edit button.
The Exclusions from rule <rule name> window opens.
- Select the check box next to the required exclusion.
- Click the Edit button.
The Add an exclusion window opens. It contains details about the selected exclusion.
- Make the necessary changes.
- Click OK to close the Add an exclusion window.
The modified record is displayed in the list of exclusions in the Exclusions from rule <rule name> window.
Deleting exclusions
You may want to delete an exclusion from an Adaptive Anomaly Control rule if, for example, you added it by mistake.
To delete exclusions from an Adaptive Anomaly Control rule:
- Proceed to the Adaptive Anomaly Control settings page.
- Select the check box next to required rule.
- Click the Edit button.
The Exclusions from rule <rule name> window opens.
- Select the check boxes next to the required exclusions
- Click Delete.
The deleted exclusions disappear from the list of exclusions in the Exclusions from rule <rule name> window.