IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Enterprise EDR: How to tune watchlists

Enterprise EDR: How to tune watchlists

Environment

  • Enterprise EDR (Formerly CB ThreatHunter) Console: All Versions

Objective

Tune watchlists at the report and IOC levels

Resolution

  1. On the Watchlists page, select a watchlist
  • To tune at the report level, click the Reports tab, select a report, then click Take Action to:
    • Include or exclude a report from detection (Disable/Enable)
    • Remove a report from a watchlist (Remove)
  • To tune at the IOC level, click the Name of the report, select an IOC, then click Take Action to include or exclude an IOC from detection (Disable/Enable)

Related Content


Was this article helpful? Yes No
50% helpful (1/2)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2597
Contributors