2022-10-20 02:27 AM
What's the best practice for dealing with false positives with regard to App Rules.
For example, we have an application that runs out of the 'AppData' directory and is unsigned. Because of this the Respond module continually alerts that it thinks that something is malicious and triggers a rule from the Endpoint Bundle.
I have a list of file hashes that are clean and not malicious that I want to 'allowlist' from these types of alerts.
I don't want to remove the meta completely from the system but I also don't want to these alerts to keep triggering.
What are my options here and what is the 'best course of action' for this case.
2022-11-03 06:28 AM
This blog post by @CodySpooner is apparently what I need to read and digest.
https://community.netwitness.com/t5/netwitness-community-blog/endpoint-bundle-tuning/ba-p/678774
2022-11-03 06:28 AM
This blog post by @CodySpooner is apparently what I need to read and digest.
https://community.netwitness.com/t5/netwitness-community-blog/endpoint-bundle-tuning/ba-p/678774