Manage IOC Detection Rules

Prev Next

Use the Indicators of Compromise (IOCs) Detection Rules dashboard to review, filter, and manage Indicators of Compromise (IOCs) detected across your server appliances or endpoints. By using this dashboard, which is now integrated with the EDR workspace, you can take immediate action on IOCs from either the EDR or Forensics workspace. This ensures that any IOC changes you make are reflected in both workspaces, giving you unified visibility and control.

How to manage IOC Detection Rules

  1. Log in to the Trellix EDR.

  2. Go to MenuIOC Detection Rules.

  3. To filter and sort IOC data:

    • Use quick filters (for example, Server ID, Operating System, Category) to narrow down results.

    • Use column-level filters or Global Search to sort and refine the data in the AG Grid.

  4. To delete IOC Rules:

    1. Select the applicable IOC rules using checkboxes. You can select up to 50 IOC rules.

    2. From the Actions drop-down menu, select Delete.

      IOC_Rules_1.png

    Note

    System-generated IOCs categorized as Mandiant Intel or Mandiant Unrestricted Intel cannot be deleted. These records are retained to maintain security, compliance, and operational requirements.

  5. To perform single row actions:

    1. Click the Settings icon at the end of a row.

      IOC_Rules_2.png
    2. Select any of the following actions.

      • Edit an IOC rule

      • Clone a rule

      • Delete a rule

      • Export a rule (CSV or XLSX)

  6. To import custom IOC rules:

    1. Click Import Rule and provide the following details.

      • Server ID

      • Operating System(s)

      • Rule file (JSON or Rule format)

      Note

      Ensure that the rule file size does not exceed 1 MB.

    2. Click Import.

  7. To export IOC data:

    • Click the Export button to export the full table in CSV or XLSX format.

    • To export an individual rule, use the Settings menu on the respective row and click Export.