Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: How to remove IOCs from custom feed report

EDR: How to remove IOCs from custom feed report

Environment

  • EDR server: All versions

Objective

Remove IOCs from a custom feed report

Resolution

  • To remove some IOCs from a report
  1. Remove IOCs from the report
  2. Update the timestamp of the report
  3. Optional: Force a feed sync - EDR: How to execute an immediate full feed sync
  • To remove an entire report
  1. Remove all IOCs from the report
  2. Update the timestamp rather than removing the report
  3. Optional: Force a feed sync - EDR: How to execute an immediate full feed sync

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
590
Contributors