Kaspersky Endpoint Agent

Changing a Sigma rule

August 27, 2024

ID 270612

You can make any changes to custom Sigma rules. You can only add or remove exclusions and change the state of Sigma rules that are supplied by Kaspersky Lab.

To edit a Sigma rule:

  1. Do one of the following:
    • for a group of protected devices, open the application policy properties window.
    • for an individual protected device, open the application settings for the device.
  2. In the Anomaly Detection using Sigma rules section, use the check box next to the name of a collection to select the collection with the Sigma rule you want to edit.
  3. Click Edit.

    The Modifying the collection rules window opens.

  4. Use the check box next to the rule name to select the rule that you want to edit.
  5. If necessary, change the rule state using the Enabled / Disabled toggle button above the rule name.
  6. Click the Modify / Edit button.

    The Changing the Sigma rule window opens.

  7. If you are editing a Sigma rule supplied by Kaspersky Lab as part of a collection, add or remove exclusions for the rule.
  8. If you are editing a custom Sigma rule, make the necessary changes throughout the entire rule structure.
  9. Click OK to save the changes.

See also

About Anomaly Detection using Sigma rules

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.