Defining Security Control Lists
Use this feature to add or remove observables in bulk.
始める前に
Role required: sn_sec_tisc.admin
手順
- Navigate to Workspaces > Threat Intelligence Security Center > Administration.
-
Go to Security Control Lists.
For example, adding observables to allow list then go to Allow list option.
- Select Allow List.
- Select the Observables type such as IP Address, File and so on to add to the allow list.
-
Click Add.
The Select Observables For Allow list is displayed.
- Select all those observables that are required to be added to the allow list.
-
Click Add to Allow List.
The selected observables are added.
- Similarly, select Add to Deny list to add the observables to the removed list.
-
Select Add to Watch list to add the observables to the watch list.
注:You can directly add the observables to allow list, deny list, or watch list directly from the Observables form view page, which are available above the form banner.
- To verify, navigate to Threat Intel Library.
-
Select the observable type that was added to the allow list.
The observable is indicated as added to allow list.注:Allow list and deny list are mutually exclusive and the system will automatically ensure that an observable in allow list is not part of deny list and vice-versa.