Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Enterprise EDR: How to tune watchlists

Enterprise EDR: How to tune watchlists

Environment

  • Enterprise EDR (Formerly CB ThreatHunter) Console: All Versions

Objective

Tune watchlists at the report and IOC levels

Resolution

  1. On the Watchlists page, select a watchlist
  • To tune at the report level, click the Reports tab, select a report, then click Take Action to:
    • Include or exclude a report from detection (Disable/Enable)
    • Remove a report from a watchlist (Remove)
  • To tune at the IOC level, click the Name of the report, select an IOC, then click Take Action to include or exclude an IOC from detection (Disable/Enable)

Related Content


Was this article helpful? Yes No
50% helpful (1/2)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2382
Contributors