You may have heard about a new threat and want to find out if your enterprise is already looking for such activity. Or you may need to find an orphaned or historical condition.
The Rules page of the Endpoint Security (HX) Web UI shows false positive rules on the Details pane of the Indicators tab and the False Positives tab. Browse either list to find a false positive rule that includes the threat condition. You can also search for false positive rules on the False Positives tab. You cannot search for false positive conditions using the CLI.
Tip
It is usually easier to search for false positive rules by their MD5 hash or filename, but you can search based on any condition or malware information in the false positive rule.
This topic describes how to search for false positive rules on the False Positives tab.
Admin, Senior Analyst, or Investigator access
Select Rules to access the Rules page of the Endpoint Security (HX) Web UI.
Select the False Positives tab.
In the Search by user, condition type, or condition value field, enter one of the following:
User—The Endpoint Security (HX) username. False positive rules provided by Trellix have the username
FireEye.Condition type—The condition type, such as
fileWriteEventCondition value—The value of the condition, such as the MD5 hash value or filename.
Click the magnifying glass on the right side of the search box or press Enter.
The list of false positive rules on the False Positives tab displays only the rules that match your search criteria.