Adding an IOA rule to the white list

Only Kaspersky Lab IOA rules can be added to the white list. If you do not want to apply a user-defined IOA rule for scanning the events database, you can disable that rule or delete it.

To add an IOA rule to the white list from the Alerts section:

  1. Select the Alerts section in the window of the program web interface.

    The table of alerts opens.

  2. Click the link in the Technologies column to open the filter configuration window.
  3. In the drop-down list on the left, select Contains.
  4. In the drop-down list on the right, select (IOA) IOA Analysis.
  5. Click the Apply button.

    The table displays alerts generated by IOA rules.

  6. Select an alert for which the Detected column shows the name of the relevant IOA rule.

    This opens a window containing information about the alert.

  7. Under Scan results, click the link with the name of the rule to open the rule information window.
  8. Click Add to white list.

    This opens a window containing information about the rule.

  9. Click the Add button.

The IOA rule is added to the white list. This rule will be skipped during events database scans.

To add an IOA rule to the white list from the Threat Hunting section:

  1. Select the Threat Hunting section in the program web interface window.

    The event search form opens.

  2. Define the search conditions and click the Search button.

    You will see a list of servers on which events meeting the defined criteria were detected.

  3. Select the relevant server.
  4. Select the event in the table containing the search results.

    This opens a window containing information about the event.

  5. Click the link in the IOA tags field.

    This opens a window containing information about the alert.

  6. Click Add to white list.

    This opens a window containing information about the rule.

  7. Click the Add button.

The IOA rule is added to the white list. This rule will be skipped during events database scans.

See also

Viewing the IOA rule table

Viewing information about an IOA rule

Enabling or disabling an IOA rule

Adding an IOA rule

Editing an IOA rule

Deleting an IOA rule

Viewing an IOA white list

Viewing information about an IOA rule in the white list

Removing an IOA rule from the white list

Viewing the IOA analysis results

Filtering and searching IOA rules

Clearing an IOA rules filter

Page top