When editing an existing IOA exclusion, what can NOT be edited?
When editing an existing IOA exclusion, the IOA name cannot be edited. An IOA (indicator of attack) exclusion allows you to define custom rules for excluding suspicious behavior from detection or prevention based on process execution, file write, network connection, or registry events. The IOA name is a predefined name that identifies the type of IOA behavior that you want to exclude, such as ''Suspicious Process Execution - Script Interpreter Executing File''. The IOA name cannot be changed when editing an existing IOA exclusion, as it is linked to a specific IOA rule in the Falcon platform.However, you can edit other parts of the IOA exclusion, such as the exclusion name, the hosts groups, and the filter criteria2.
Limited Time Offer
25%
Off
Izetta
9 months agoCelestina
10 months agoMoira
10 months agoJoni
10 months agoCelestina
10 months agoRoselle
10 months agoTy
10 months agoDell
11 months agoRoselle
11 months ago