You can add individual conditions to create custom indicator rules that monitor host endpoints for activity related to network connections, DNS lookups, and creation or modification of specific files.
Regular expressions you use in your custom indicator rules are validated if the regex is for a file path condition that uses the matches operator. If the regex is invalid, the following message appears at the top of the Endpoint Security (HX) Web UI:
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Maintain custom indicator rules
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Threat detection using IOC rules > Threat detection using IOC rules in the Forensics workspace > Maintain custom indicator rules > Create custom indicator rules by manually adding conditions