The Service Config view > Indicators of Compromise tab for the Security Analytics Malware Analysis provides a way to configure the way each of the four scoring modules uses the available rules to score data.
This is an example of the Indicators of Compromise tab.
The Indicators of Compromise tab consists of a toolbar and pageable grid.
This table describes the features of the grid.
|Module selection list||Selects the scoring module for which you want to view the Indicators of Compromise: All, Network, Static, Community, Sandbox, or Yara.|
|Description search field||Type text for which you are searching in the Description field.|
|Search button||Filters the grid to display only Descriptions that match the Description search term.|
|Enable All button||Click to enable all rules for the scoring module, as opposed to enabling all rules on the page using the checkbox.|
|Enable button||Click to enable selected rules.|
|Disable All button||Click to disable all rules for the scoring module, as opposed to disabling all rules on the page using the checkbox.|
|Disable button||Click to disable selected rules.|
|Reset All button||Click to reset all rows on the page to their default values.|
|Reset button||Click to reset selected rows to their default values.|
|Save button||Click to save changes you made on this page. If you leave the page without saving, the changes are lost. The description of each row with unsaved changes has a red corner.|
This table describes the features of the toolbar.
|Selection checkbox||Checkboxes for selecting individual rows or all rows on the page.|
|Enabled checkbox||If the indicator of compromise is enabled, Security Analytics Malware Analysis uses the rule for scoring session data.|
|High Confidence checkbox||If checked, Security Analytics Malware Analysis treats the rule as one very likely to indicate the presence of malware, and an event that triggers that rule is marked in the results grid.|
|Description||Describes the Indicator of Compromise.|
|Score||Specifies the score that you want to factor in to the total score for any event that triggers the rule. The default score is displayed and you can raise or lower the score by dragging the slider or typing a number in the score box.|
|File Type||Displays the file types to which the rule applies. Possible values are ALL, PDF, MS Office, and Windows PE.|