When editing an existing IOA exclusion, what can NOT be edited?
When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as ''Suspicious Process Execution - Script Interpreter Executing File''. The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform.However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria2.
Limited Time Offer
25%
Off
Izetta
6 months agoCelestina
6 months agoMoira
6 months agoJoni
6 months agoCelestina
6 months agoRoselle
6 months agoTy
6 months agoDell
7 months agoRoselle
7 months ago