The following types of false positive rules are supported. These types may appear in the Rule Type column on the False Positives tab of the Rules page in the Endpoint Security (HX) Web UI.
Type | Description |
|---|---|
IOC | Identifies a false positive rule for an indicator of compromise (IOC) condition. |
EXD | Identifies a false positive rule for an exploit alert. |
MAL | Identifies a false positive rule for information from a malware alert. |
For information about managing false positive rules, see Managing false positive rules .