Defining false positive rules on the Triage Summary page

Prev Next

You can mark an indicator of compromise (IOC) or exploit (XPLT) alert as false positive in the Triage Summary page using the following procedure.

To define an IOC or XPLT alert as false positive rule on the Triage Summary page:
  1. Open a triage summary from either the Hosts page or the Acquisitions page. For more information, see Reviewing triage collections in the Triage Viewer .

  2. Select an Alerting Process in the left hand pane. An example is shown in the figure below.

    HX_TriageAlertProcess.png
  3. In the details pane on the right, click the badge for the alert condition that you want to mark as a false positive. In the example below, we have selected the Presence (PRS) alert bade.

    The Details dialog box opens.

    HX_triage_markFP.png
  4. Click Mark as false positive.