Creating exclusions from Kaspersky IOA rules

March 20, 2024

ID 226703

Expand all | Collapse all

You can create exclusions from rules made by Kaspersky from alert details and event details. If you do not want to use a created exclusion for scanning events, you can delete it.

To create an exclusion from alert details:

  1. Do one of the following:
    • In the main menu, go to MONITORING & REPORTING → Alerts, and then open the details of the alert that is triggered by the Kaspersky IOA rule.
    • In the main menu, go to MONITORING & REPORTING → Threat hunting, and then open the details of the event that is triggered by the Kaspersky IOA rule.
  2. Make the necessary changes in the following fields:
    • Use
    • Action
  3. Click the Save button.

The exclusion is created. You can view and manage exclusions in the Custom rules section.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.