You can create exclusions from rules made by Kaspersky from alert details and event details. If you do not want to use a created exclusion for scanning events, you can delete it.
To create an exclusion from alert details:
Do one of the following:
In the main menu, go to MONITORING & REPORTING→ Alerts, and then open the details of the alert that is triggered by the Kaspersky IOA rule.
In the main menu, go to MONITORING & REPORTING→ Threat hunting, and then open the details of the event that is triggered by the Kaspersky IOA rule.
Make the necessary changes in the following fields:
Always. The Kaspersky rule is used in events database scans.
With exclusions. The Kaspersky rule is used with exclusions in events database scans. Choosing this value opens a field for entering a condition or editing it.
Never. The Kaspersky rule is not used in events database scans.
By default, the Always value is set. If you change the value in the field, an exclusion from Kaspersky rule is created.