AI Manuel Exclusions
Last updated
Last updated
On the portal, users can use AI to ask questions about portal futures, and artifact analysis and classify the artifact automatically.
Question Wizard is designed for users frequently asking questions about portal management. Users can manage sysmon data, process traffic status, threat analysis results, and AI enrichments. To use the Question Wizard, please click on the robot button on the upper right of the page.
After clicking the robot button, the Question Wizard modal will appear on the screen. Users can select predefined questions.
After the selection, users can exclude the artifacts. Just do these three steps:
1 - Click on the "Check All Recommended",
2 - Click on the "Add All Checked to Image & Network Access Exclusions",
3 - Click on the "Add All Checked to Exclusions (per Relevant Event ID)".
These actions will check all the recommended artifacts and add them to the specific exclusion fields. With those actions, the unnecessary sysmon artifacts are excluded from the collection and analysis.
The sysmon exclusion lists can be observed from "Rules & Policies" -> "Artifact Collection Parameters" -> "Windows Sysmon Rules".