Maintain custom indicator rules

Prev Next

You can use the Endpoint Security (HX) Web UI to create custom indicator rules in either of the following ways:

Custom indicator rules can also be edited after they have been created. See Editing custom indicator rules using the Web UI.

You cannot create or edit custom indicator rules using the CLI.

Important

Endpoint Security (HX) version 4.8 or later supports the creation of custom indicator rules for Linux conditions (network events only).

The Endpoint Security (HX) rejects indicators of compromise (IOCs) that contain only a single negated condition. This avoids a potential false positive storm caused by the negated condition. For example, a false positive storm could be caused by an IOC that includes only a single condition that triggers an alert when an MD5 hash is not a specific value.

Prerequisites
  • Admin access

  • If you elect to create a custom indicator rule by uploading a list of conditions, one or more properly formatted lists of conditions must already be created