Using default lists

Prev Next

Several Trellix rules contain logic referencing lists that you must build. If the lists are not populated, the rule may not function as intended or may not work at all. One example is the home.nets list, which some rules reference and should contain a list of network ranges owned or used by customer systems.

When reviewing enabled rules or making a decision to enable one, make note of any reference to lists like these so that you can use the rule to its fullest capability.

To use these rules, reference the table below that contains default lists and their corresponding rules.

List name

Description

Related rules

dnp3.clients

Store IP addresses for known DNP3 clients.

DNP3 PROTOCOL [Authorized Cold Restart]

DNP3 PROTOCOL [Unauthorized Cold Restart]

DNP3 PROTOCOL [Unauthorized Read Request]

DNP3 PROTOCOL [Unauthorized Write Request]

DNP3 PROTOCOL [Unauthorized Miscellaneous Request]

exclusions.global.serviceinstall

Store exclusions for file paths used in Windows service installations.

WINDOWS METHODOLOGY [Service Installation]

home.nets

Define the network ranges that are owned or utilized by customer systems.

Most rules in Web App Attacks rulepack

technical.proc.host.whitelist

Exclude hosts from triggering the “WINDOWS METHODOLOGY [Technical Proc by Non-Technical User]” rule.

WINDOWS METHODOLOGY [Technical Proc by Non-Technical User]

technical.users

Define a list of user names that would be considered “technical.”

WINDOWS METHODOLOGY [Technical Proc by Non-Technical User]

windows.domains

Define a list of legitimate Windows domain names used at an organization.

WINDOWS METHODOLOGY [Local PTH Success]

WINDOWS METHODOLOGY [Local PTH Failure]

windows.privileged.accounts

Define a list of accounts that are deemed privileged, or ones that have a higher level of access.

WINDOWS METHODOLOGY [Excessive Logons - Privileged Accounts]