|
Export a rule to a .json file. |
You can export detection rules from any of the following rule categories: Custom, Endpoint Defense Experimental, Endpoint Defense Exclusion, Endpoint Defense macOS Official, Endpoint Defense Windows Official.
Click for a rule. |
|
Import a custom detection rule from a .json file. |
- Click Import Rule.
- Browse to and select or drag and drop the .json file. Click Import.
- Change the rule configuration and syntax as required.
- Click Validate.
- Click Publish.
To edit a custom rule after it has been published, click for the rule. |
|
Clone and modify a detection rule. |
You can clone detection rules from any of the following rule categories: Custom, Endpoint Defense Experimental, Endpoint Defense Exclusion, Endpoint Defense macOS Official, Endpoint Defense Windows Official.
- Click
for a rule.
- Change the rule configuration and syntax as required.
- Click Validate.
- Click Publish.
|
|
Delete a custom rule. |
You can delete rules from the Custom category only.
- Click
for a rule.
- Click Confirm Delete.
|