You can add malware attacks to the malware policy generated from an admin domain. This policy will be updated for that admin domain only.
Steps:
Navigate to Analysis → <Admin Domain Name> → Attack Log.
Select the alert, click Other Actions at the bottom of the page.
Select Update Policy, and click (Malware) /<Admin Domain Name>/<Malware Policy>.
The <Attack Name> panel opens.
Make the required changes to the policy settings and click Update.
The attack is added to the malware policy of that admin domain.
To view/edit the attack added to the malware policy:
Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → Advanced Malware.
Double-click on the policy.
The Advanced Malware page opens.
Note
The attacks added to the policies do not come into effect immediately. You have to update the Sensor for a policy update from Deploy Pending Changes.
For more information on malware policies, see the section Advanced Malware Policies.