You can use the Endpoint Security (HX) Web UI to create custom indicator rules in either of the following ways:
You can create a custom indicator rule by manually adding individual conditions. These individual conditions can monitor host endpoints for activity related to network connections, DNS lookups, and creation or modification of specific files. See Creating custom indicator rules by manually adding conditions.
You can create a custom indicator rule by uploading lists of conditions. See Creating custom indicator rules by uploading lists of conditions.
Custom indicator rules can also be edited after they have been created. See Editing custom indicator rules using the Web UI.
You cannot create or edit custom indicator rules using the CLI.
Important
Endpoint Security (HX) version 4.8 or later supports the creation of custom indicator rules for Linux conditions (network events only).
The Endpoint Security (HX) rejects indicators of compromise (IOCs) that contain only a single negated condition. This avoids a potential false positive storm caused by the negated condition. For example, a false positive storm could be caused by an IOC that includes only a single condition that triggers an alert when an MD5 hash is not a specific value.
Admin access
If you elect to create a custom indicator rule by uploading a list of conditions, one or more properly formatted lists of conditions must already be created