This topic shows you how to edit a custom indicator rule by adding and deleting individual conditions or by uploading one or more lists of conditions.
Note
After creating an indicator, you cannot change the operating systems to which it applies. To change the operating system, create one or more new indicator rules for the individual operating system and then, if appropriate, delete the original indicator.
Admin access
Select Rules from the Configure section of the main menu to access the Rules page.
On the Indicators tab, in the Indicators grid, select the checkbox to the left of the Custom Indicator that you want to edit.
In the Actions list, click Edit indicator, and then click Go.
The Edit Indicators page opens.
To add individual conditions:
Under add individual conditions, in the Look for list, select the relevant option, and then click Add.
In the Look for [option] dialog box, enter the appropriate values and operators, and then click Add.
To add one or more lists of conditions:
On the Create Indicator page, under 1. Define indicator, go to upload a list of conditions. Click the Browse button next to the Browse for intel file box, and locate and select a file to upload.
Click Upload.
Select one of the following options:
To add the conditions in the new list to the existing indicator, select Append to indicator.
To replace the conditions in the existing indicator, select Replace all conditions.
To upload additional lists of conditions:, repeat the previous step. To add individual conditions, follow the instructions in Step 4. Make sure that the Append to indicator option is selected.
Repeat until you have added all the new conditions that you want to include in the indicator.
In the preview pane, check the conditions.
Important
If you mistakenly entered only part of an MD5 hash or IP address, the entry may appear as a hostname in a condition. To avoid conflicts with existing hostnames, Trellix recommends that you delete such conditions.
In the preview pane, hover over unnecessary conditions and click the x icon in the upper right corner to delete them.
(Optional) Under 2. Describe indicator, you can add or update a description of the indicator.
This description appears on the Indicator Details tab in the details area for the indicator rule on the Rules page.
Click Save.
Your updated indicator rule appears on the Indicators tab of the Rules page.