You can separately classify alerts with executables hash files. You can either allow or block it. When an executable hash file is seen for the first time in the network, you have the option to unclassify it and send it for further analysis. You can later perform forensics for these hash files.
Task
- Navigate to Analysis → <Admin Domain Name> → Attack Log.
- Select the alert whose file hash you want to allow or block or unclassify.
-
Click
Other Actions, select
Create Exception, and click
Reclassify Endpoint Executable: <hash file>.
A confirmation message is displayed.
-
Click
Yes.
A successfully allowed/blocked/unclassified message is displayed.
You can view/edit the endpoint executable file hash under Analysis → <Admin Domain Name> → Endpoint Executables.
For more information on endpoint executable file hash, see Analyze Endpoint Executables.