Creating exclusions from Kaspersky IOA rules

Expand all | Collapse all

You can create exclusions from rules made by Kaspersky from alert details and event details. If you do not want to use a created exclusion for scanning events, you can delete it.

To create an exclusion from alert details:

  1. Do one of the following:
    • In the main menu, go to MONITORING & REPORTING → Alerts, and then open the details of the alert that is triggered by the Kaspersky IOA rule.
    • In the main menu, go to MONITORING & REPORTING → Threat hunting, and then open the details of the event that is triggered by the Kaspersky IOA rule.
  2. Make the necessary changes in the following fields:
    • Use
    • Action
  3. Click the Save button.

The exclusion is created. You can view and manage exclusions in the Custom rules section.

Page top