Changing a Sigma rule

You can make any changes to custom Sigma rules. You can only add or remove exclusions and change the state of Sigma rules that are supplied by Kaspersky Lab.

To edit a Sigma rule:

  1. In the main window of the Web Console, select Assets (Devices)Policies & profiles.
  2. Click the name of the Kaspersky Industrial CyberSecurity for Nodes policy.

    The policy properties window opens.

  3. Select the Application settings tab.
  4. In the Anomaly Detection using Sigma rules section, use the check box next to the name of a collection to select the collection with the Sigma rule you want to edit.
  5. Click Edit.

    The Changing the Sigma rules collection window opens.

  6. Use the check box next to the rule name to select the rule that you want to edit.
  7. If necessary, change the rule state using the Enabled / Disabled toggle button above the rule name.
  8. Click Edit.

    The Changing the Sigma rule window opens.

  9. If you are editing a Sigma rule supplied by Kaspersky Lab as part of a collection, add or remove exclusions for the rule.
  10. If you are editing a custom Sigma rule, make the necessary changes throughout the entire rule structure.
  11. Click OK to save the changes.
Page top