-
Excluding Commands using Wildcards in Advanced Breach Detection
Advanced Breach Detection can be configured to whitelist certain commands that run repetitively but have changing command line parameters. The ability to whitelist these commands should be done from the configuration screen of the app. From the RocketCyber Dashboard locate the Advanced Breach Detection App Card Click…
-
Whitelisting App Results
Whitelisting allows you to customize your result view to each customer While there are many use cases for excluding detections from the results, the most common customer request was the ability to still detect a specific Suspicious/Malicious finding and exclude it when it meets given criteria. Whitelisting can be performed…
-
Custom Whitelisting Beta
Whitelist cloud apps based on combinations of fields Motivation So you want to whitelist network tools, but only for your network administrators? Something like email = 'admin1@company.com' OR 'admin2@company.com' AND malicious_file_name = 'PuTTy' How To * Select an app result of the type you would like to whitelist, and…