Custom Rules
Custom Rules allows you to save queries as a rule Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session. to generate Infinity XDR
Extended Detection & Response/XPR
Extended Prevention & Response incidents when a Threat Hunting event matches the rule.
To create a custom rule:
-
Go to Investigate > Threat Hunting.
-
Run a query and click the
icon from the top right corner of the page.
-
In the Rule name field, enter a rule name.
-
In the Attack name field, enter a name. For example, Emotet.
The system prefixes XDR.CUSTOM to the attack name, for example XDR.CUSTOM.Emotet. This is useful in finding insights and incidents generated by a custom rule.
-
From the Confidence field, select a confidence level for the detection.
-
From the Severity field, select a severity level for the incident.
-
In the Description field, enter a description for the rule.
-
(Optional) In the Comment field, enter comment, if any.
-
To generate incidents if the Threat Hunting events match the custom rule, toggle Status to On. Otherwise, the custom rule is only saved and does not generate incidents upon matching activity.
-
Click Add.
-
To view all custom rules created, go to Policy > Custom Rules.
Column Name
Description
Status
Indicates whether the custom rule is enabled or not.
Rule Name
Name of the rule.
Confidence
Confidence level of the detection.
Severity
Severity of the detection.
Attack Name
Name of the attack.
Description
Description of the rule.
Creator
Name of the person that created the rule.
Creation Date
Date and time when the rule was created.
Date Last Edited
Date on which the rule was last modified.
Comment
Comment about the rule.
To export the rules to an excel in CSV format, click Export All (CSV).
Managing Custom Rules
To edit a custom rule:
-
Go to Policy > Custom rules.
-
Select the rule you want to edit and click Edit in Threat Hunting.
The system redirects you to the Threat Hunting page that shows the custom rule and the query.
-
Edit the custom rule and click Update.
To delete a rule:
-
Select the rule you want to delete and click Delete.
-
Click Yes in the confirmation dialog.
Running a Custom Rule
To manually run the Custom Rule:
-
Go to Policy > Custom rules.
-
Select the rule and click Run in Threat Hunting.
The system redirects you to the Threat Hunting page that shows the custom rule and the query.