Ignoring Malware from Toxic Combinations
When CloudGuard calculates the Risk Score for a Toxic Combination, CloudGuard considers malware families it identifies in your cloud assets. You can configure CloudGuard to ignore a specific malware family from the Toxic Combinations calculation for an Entity, Organizational Unit, or Environment. Ignore a malware family if you do not want to focus on it in your investigation. After you ignore a malware family, CloudGuard may assign a lower risk score to a Toxic Combination or remove it from the Toxic Combinations table.

-
From the left menu, go to Risk Management > Toxic Combinations.
-
Select a Toxic Combination.
A sliding window opens.
-
In the sliding window, expand the Vulnerabilities section.
-
To the right of the relevant malware family, click Ignore.
The New Malware Ignore Item window opens.
-
Optional - Enter or edit one or more of these attributes of the Malware Ignore Item:
-
Name
-
Description
-
Expiration Date - By default, the Malware Ignore Item is permanent.
Note - The Malware IDs section and the Vulnerable Entity section are filled automatically. To add more malware families or entities to the Malware Ignore Item, see To ignore one or more malware families from Toxic Combinations for multiple entities.
-
-
Click Save.

-
From the left menu, go to Risk Management > Toxic Combinations.
-
Click Malware Ignore List.
-
Click Add.
The New Malware Ignore Item window opens.
-
Enter a name for the Malware Ignore Item.
-
Optional - Enter or edit one or more of these attributes of the Malware Ignore Item:
-
Description
-
Expiration Date - By default, the Malware Ignore Item is permanent.
-
-
In the Malware Details section, click the + (plus sign) button.
-
Enter the relevant Malware ID for the malware family.
-
Optional - Add more malware IDs to the Malware Ignore Item.
-
In the Vulnerable Entity section, select where to ignore the malware:
-
To ignore the malware from all entities in one or more Organizational Units, select Organizational Unit and enter the names of the Organizational Unit(s).
-
To ignore the malware from all entities in one or more Environments, select Environment and enter the names of the Environment(s).
-
To ignore the malware from one or more specific entities, select Entity Name or Entity ID and enter the names or IDs of one or more Entities.
-
-
Click Save.

-
From the left menu, expand Risk Management > expand Toxic Combinations.
-
Click Malware Ignore List.
-
Click the name of the Malware Ignore Item.
A sliding window opens.
-
Edit the Malware Ignore Item.
-
Click Save.

-
From the left menu, go to Risk Management > Toxic Combinations.
-
Click Malware Ignore List.
-
Select the checkbox to the left of the name of the Malware Ignore Item.
-
Click Delete.
-
In the confirmation window, click Delete.