Create custom indicator rules by manually adding conditions

Prev Next

You can add individual conditions to create custom indicator rules that monitor host endpoints for activity related to network connections, DNS lookups, and creation or modification of specific files.

Regular expressions you use in your custom indicator rules are validated if the regex is for a file path condition that uses the matches operator. If the regex is invalid, the following message appears at the top of the Endpoint Security (HX) Web UI:

InvalidRegex.png