You can enable and disable the generation of Endpoint Security (HX) appliance indicator rules from Network Security, Email Security, File Protect, and Malware Analysis appliance alerts, which include alerts on malware callback traffic and host infections. These indicator rules are also referred to as noisy alert indicator rules.
False positives can result when noisy alert indicator rules are enabled. False positives include commonly visited domains that are not malicious, false positive registry entries, and file MD5 indicator rules. Enable the generation of noisy alert indicator rules if you feel you can manage the possibility of false positives. They are disabled by default.
Admin access