Several Trellix rules contain logic referencing lists that you must build. If the lists are not populated, the rule may not function as intended or may not work at all. One example is the home.nets list, which some rules reference and should contain a list of network ranges owned or used by customer systems.
When reviewing enabled rules or making a decision to enable one, make note of any reference to lists like these so that you can use the rule to its fullest capability.
To use these rules, reference the table below that contains default lists and their corresponding rules.
List name | Description | Related rules |
|---|---|---|
| Store IP addresses for known DNP3 clients. | DNP3 PROTOCOL [Authorized Cold Restart] DNP3 PROTOCOL [Unauthorized Cold Restart] DNP3 PROTOCOL [Unauthorized Read Request] DNP3 PROTOCOL [Unauthorized Write Request] DNP3 PROTOCOL [Unauthorized Miscellaneous Request] |
| Store exclusions for file paths used in Windows service installations. | WINDOWS METHODOLOGY [Service Installation] |
| Define the network ranges that are owned or utilized by customer systems. | Most rules in Web App Attacks rulepack |
| Exclude hosts from triggering the “WINDOWS METHODOLOGY [Technical Proc by Non-Technical User]” rule. | WINDOWS METHODOLOGY [Technical Proc by Non-Technical User] |
| Define a list of user names that would be considered “technical.” | WINDOWS METHODOLOGY [Technical Proc by Non-Technical User] |
| Define a list of legitimate Windows domain names used at an organization. | WINDOWS METHODOLOGY [Local PTH Success] WINDOWS METHODOLOGY [Local PTH Failure] |
| Define a list of accounts that are deemed privileged, or ones that have a higher level of access. | WINDOWS METHODOLOGY [Excessive Logons - Privileged Accounts] |