You can define the following types of false positive rules.
You can mark a condition in an indicator of compromise (IOC) rule as false positive to define an IOC false positive rule. This will remove the condition from any existing IOC rules and mark the condition as false positive in future IOC rules. The Endpoint Security (HX) automatically marks any alerts associated with the IOC false positive rule with a false positive badge . Whether it removes the alert depends on your specifications when you define the IOC false positive rule.
You can mark information in a malware (MAL) alert as false positive to define a malware false positive rule. Endpoint Security (HX) marks malware alerts associated with malware false positive rules with a false positive badge. Whether it removes the alert depends on your specifications when you define the malware false positive rule.
You can mark information in an exploit (XPLT) alert as false positive to define a new false positive rule. The Endpoint Security (HX) marks exploit alerts associated with exploit false positive rules with a false positive badge . Whether it removes the alert depends specifications when you define the exploit false positive rule.
False positive rules can be defined in the following ways using the Endpoint Security (HX) Web UI. They cannot be defined using the CLI.